Call it OpenClaw, call it Clawdpot, but most of all call out the security risks

Unless you have been living the life of an offline hermit, you can’t have missed the social media hyperbole surrounding this most bizarre of AI experiments. You might have called it Clawdbot, until trademark concerns necessitated a name change to Moltbot. Now, apparently, you should call it OpenClaw: “Trademark searches came back clear, domains have been purchased, migration code has been written,” according to its creator, Peter Steinberger.

I’m here today to say that while names should never hurt you, ignoring security sticks and stones could. Welcome to the wonderful world that I inhabit, where viral AI tools intersect with real cybersecurity concerns.

I’m not stating categorically that OpenClaw is a danger. Nope, I’m merely pointing out that ignoring the dangers it can bring is, erm, a danger. Sadly, that appears to be precisely what otherwise sensible folk of my acquaintance are doing as they get wrapped up in the viral hype, and in so doing don’t appreciate the risk that they are getting tangled up in.

So, let me explain, with the help of a couple of highly respected cybersecurity professionals, just where that risk sits.

The OpenClaw security risk, part one

Bullet point one is the most obvious: this is an AI agent. A brilliant, automated, timesaving one at that. Anna Gutowska, an AI engineer at IBM, defines an AI agent as “a system that autonomously performs tasks by designing workflows with available tools”. More critically in the context of this article, she goes on to explain how such an agent can do so with minimal human oversight.

You don’t have to be a cybersecurity veteran with more than three decades of experience to understand that this could be problematic. Former NATO advisor, and current Chief Security Officer (EMEA North) at Palo Alto Networks, Jesper Olsen, has the experience in droves.

“For it to function as designed,” Olsen told me, these agents “need access to your root files, to authentication credentials, both passwords and API secrets, your browser history and cookies, and all files and folders on your system.” Concerned yet? You should be, and it gets better, or should that be worse?

“The interconnection with those AI agents isn’t necessarily secure,” Olsen warned. “We see it represents a lethal trifecta of vulnerabilities: access to private data, exposure to untrusted content, and the ability to communicate externally.”

Careful what you delegate to an AI agent like OpenClaw

Bullet point number two is no less concerning. Be careful what you ask such an agent to do, what you give it access to, and how that might play out.

This is one of the use cases that people are crowing about online, letting these bots deal with their email. Wowser.  “Giving it full access to all of your emails may seem fine and might make sense since you want it to act as your personal assistant, “ warned Erich Kron, CISO Advisor at KnowBe4. “However, there is real danger, not just from malicious use but accidental, when giving AI agents this type of access.”

As Kron told me, ”in the blink of an eye, it could be deleting your emails, or taking malicious actions such as siphoning off data to bad actors”.

That won’t happen, you say? Well, we’ve already seen examples of misconfigured control panels openly leaking private data. As a Bitdefender investigation put it, “these control panels effectively served as master keys to the digital environments they managed”.

OpenClaw security risk bullet point three

I don’t think there needs to be a bullet point three, frankly. If you aren’t already concerned enough to consider the security risk, you aren’t going to be persuaded by anything else. Until your organisation is impacted, of course, and it will be too late then.

“Malicious payloads no longer need immediate execution,” Olden explained, “they can sit in context for weeks, waiting. The level of autonomy with such AI agents, if not governed, can give rise to irreversible security incidents.”

As Olsen concluded, and I couldn’t agree more, “the attack surface continues to remain unmanageable and unpredictable”. And unmanageable and unpredictable, dear reader, is the very definition of risk.

I’m not saying don’t explore what is, without doubt, an interesting development in AI tooling. Just be aware of the risks that come along for the ride. If you’re going to take a look, do so in a sandboxed environment while you get acquainted with the thing.

“I’d like to thank all security folks for their hard work in helping us harden the project,” Steinberger said. “We’ve released machine-checkable security models this week and are continuing to work on additional security improvements.

“Remember that prompt injection is still an industry-wide unsolved problem, so it’s important to use strong models and to study our security best practices.”

You can find those here and I would recommend all users read them before employing this, or any, AI agent, to be honest.

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.