logoalt Hacker News

kylegalbraithtoday at 7:20 AM4 repliesview on HN

What’s the security situation around OpenClaw today? It was just a week or two ago that there was a ton of concern around its security given how much access you give it.


Replies

ricardobayestoday at 7:28 AM

Can only reasonably be described as "shitshow".

mcintyre1994today at 7:54 AM

I don’t think there’s any solution to what SimonW calls the lethal trifecta with it, so I’d say that’s still pretty impossible.

I saw on The Verve that they partnered with the company that repeatedly disclosed security vulnerabilities to try to make skills more secure though which is interesting: https://openclaw.ai/blog/virustotal-partnership

I’m guessing most of that malware was really obvious, people just weren’t looking, so it’s probably found a lot. But I also suspect it’s essentially impossible to actually reliably find malware in LLM skills by using an LLM.

kolja005today at 7:51 AM

My company has the github page for it blocked. They block lots of AI-related things but that's the only one I've seen where they straight up blocked viewing the source code for it at work.

bowsamictoday at 7:23 AM

Many companies have totally banned it. For example at Qt it is banned on all company devices and networks