OpenClaw is amazing and you probably shouldn't run it
I get the appeal.
Andrej Karpathy called it âthe most incredible sci-fi takeoff-adjacent thingâ heâd seen recently. The creator, Peter Steinberger, is a respected developer whose PDF SDK is approaching 1 billion devices. OpenClaw (formerly Clawdbot, briefly Moltbot) hit 145,000 GitHub stars in weeks. People are buying Mac Minis specifically to run it.
Itâs also, according to security researchers at Cisco, Palo Alto Networks, and Google, a security nightmare with documented CVEs, 21,000+ exposed instances leaking credentials, and 341 malicious plugins distributing macOS malware.
Both things can be true.
What makes OpenClaw different
Most AI assistants stay safely in their lane. They answer questions, write code, maybe generate images. They donât actually do anything beyond the conversation.
OpenClaw does things. It runs on your machine with shell access. It reads your files, executes commands, controls your browser, manages your email and calendar. You can message it through WhatsApp or Telegram, and itâll handle tasks autonomously. It remembers context across weeks. It can book flights, negotiate purchases, manage your inbox.
Itâs what people have been promising AI assistants would be for years.
The technical term for this is âagentic AIâ - systems that donât just respond but take action. The security term for it is âexpanded attack surface.â
The documented dangers
Letâs be specific about what security researchers have found:
CVE-2026-25253: One-click remote code execution
Discovered by Mav Levin at DepthFirst, this CVSS 8.8 high-severity vulnerability lets an attacker completely compromise your system through a single malicious link. Click a URL, visit a webpage that redirects you, and milliseconds later your authentication token is stolen, your sandbox is disabled, and an attacker has shell access to your machine.
The vulnerability was patched in version 2026.1.29, but it illustrates the architectural challenges here.
21,000+ publicly exposed instances
Censys researchers found over 21,000 publicly accessible OpenClaw instances running without authentication. Not all were vulnerable, but many were exposing API keys, private messages, and configuration data to anyone who stumbled across them.
The tool is designed to run locally, bound to localhost. But the gap between design and deployment is where security breaks down.
341 malicious skills distributing malware
Security firm Koi discovered 341 malicious skills on ClawHub (OpenClawâs skill marketplace), with 335 belonging to a coordinated campaign called ClawHavoc. These skills had professional documentation and names like âsolana-wallet-trackerâ or âyoutube-summarize-pro.â They instructed users to download âprerequisitesâ that were actually Atomic Stealer (AMOS), a macOS infostealer that harvests credentials and API keys.
ClawHub allows anyone with a week-old GitHub account to upload skills. Thereâs a reporting feature now, but no code review or vetting process.
Ciscoâs findings
Ciscoâs AI Threat Research team tested a malicious skill against OpenClaw and reported 9 security findings - 2 critical, 5 high severity. The skill, mockingly named âWhat Would Elon Do?â, was functionally malware. It silently exfiltrated data to external servers and used direct prompt injection to bypass safety guidelines. That skill had been downloaded thousands of times before it was caught.
What the experts say
Heather Adkins, VP of Security Engineering at Google Cloud: âMy threat model is not your threat model, but it should be. Donât run Clawdbot.â
Gary Marcus: âIf you care about the security of your device or the privacy of your data, donât use OpenClaw. Period.â
Palo Alto Networks identified what security researchers call a dangerous combination: access to private data, exposure to untrusted content, and the ability to communicate externally.
The projectâs own documentation acknowledges the risks: âRunning an AI agent with shell access on your machine is⌠spicyâ and âThere is no âperfectly secureâ setup.â
If youâre going to run it anyway
I know some of you will. I get it. The technology is genuinely fascinating. Hereâs how to reduce the risk:
Never run it on your primary machine. Use a dedicated device, a VM, or a cloud instance. If it gets compromised, it should only take down things youâre willing to lose.
Treat every skill as malicious until proven otherwise. Donât install skills from ClawHub without reading the code. Even then, understand that sophisticated attacks hide well.
Use the built-in security features. Enable sandboxing. Set gateway.auth.password. Use strict tool allowlists. Disable exec approvals only for specific, trusted scenarios.
Keep it updated. Security patches are being released regularly. If youâre running an old version, youâre running known vulnerabilities.
Consider the DigitalOcean 1-Click Deploy. If youâre not comfortable with command-line security configuration, the one-click deployment handles some basics. Itâs not perfect, but itâs better than exposing a misconfigured instance.
Never run with root access. Seriously. The blast radius of a compromise is proportional to the permissions you grant.
Monitor what itâs doing. Check logs. Watch network traffic. Audit the commands itâs executing. If you canât do this, you canât safely run an autonomous agent.
The broader pattern
OpenClaw isnât unique in its security challenges. Itâs just the most visible example right now of a fundamental tension in agentic AI: the same capabilities that make these systems useful - broad access, autonomous action, persistent memory - are exactly what make them dangerous when compromised.
Weâre building systems that need to act as us, with our permissions, across our tools. We havenât figured out how to do that safely at scale. Weâre still in the âmove fast and break thingsâ phase, but the things that break now include your email, your bank access, and your private data.
Maybe thatâs okay for hobbyists and early adopters who understand the risks. Maybe itâs an acceptable trade-off for the productivity gains. Maybe weâll develop better security models as the technology matures.
Or maybe we wonât. Maybe the fundamental architecture of âgive the AI full access and hope the guardrails holdâ is flawed. Maybe we need something more like capability-based security, where permissions are granular and revocable. Maybe we need formal verification of agent behavior, not just vibes and testing.
I donât know. These are genuine questions, not rhetorical ones.
The thing is
Peter Steinberger has been remarkably transparent about the security challenges. The maintainers have been responsive to vulnerability reports. The community has built security scanning tools. This isnât a case of bad actors or negligence.
This is what it looks like when a powerful new capability arrives faster than our ability to secure it. When the technology is so compelling that people use it despite the warnings. When the gap between âthis is amazingâ and âthis is safeâ is measured in months, not years.
OpenClaw works. Thatâs not in question. Itâs genuinely impressive technology that points toward a real future for AI assistants.
The question isnât whether OpenClaw is interesting. It is. The question is whether weâre ready to run systems like this safely. Whether we have the infrastructure, the tooling, the security models, the user education.
Right now? I donât think we do.
But I understand why people are trying anyway. Sometimes you learn more from running the experiment than from thinking about it. Sometimes the only way to figure out what guardrails we need is to find out what happens when we donât have them.
Just⌠do it on a machine you donât care about losing. And maybe not the one with your bank credentials.
The rain will stop. But that doesnât mean you should stand outside without an umbrella.