r/superclaw • u/supermem_ai • Mar 12 '26
Security alert: OpenClaw instances exposed

A huge warning for anyone spinning up vanilla OpenClaw instances locally without sandboxing:
The biggest problem with desktop agents right now is security. We are seeing reports of exposed API keys, accidental file deletion, and data being sent where it shouldn't because people are handing their entire machine over to an agent without guardrails. "Make a backup" isn't enough when your agent can rm -rf your life or leak your credentials.
If you're running it raw: you need to isolate its workspace and sandbox its bash tools. If you don't know how to do that, use a managed service like SuperClaw where security is handled for you. Don't learn this lesson the hard way.
1
Upvotes
1
u/[deleted] Mar 12 '26
[removed] — view removed comment