OpenClaw is an open-source AI agent that runs on your local machine and takes actions on your behalf. It can execute terminal commands, edit files, drive your browser, and call APIs. In principle, it is what most people mean when they talk about "an AI that actually does things." In practice, it is the case study for why the current agent ecosystem is not yet safe to point at your business.
This is a different call than the Claude Cowork playbook posted earlier this month. Cowork is imperfect but built by a single company that owns both the product and the safety posture. OpenClaw is an open-source project with a community skills ecosystem that inherits your credentials and permissions. That difference is the whole article.
The receipts
What has actually happened in the wild in the last six months.
- BitSight scanned the internet for exposed OpenClaw instances and found more than 30,000 with weak or missing authentication. Any of those instances can be talked to by a stranger who finds the port.
- ZeroLeaks extracted OpenClaw's system prompt with an 84.6 percent success rate using a simple JSON-formatted request against the default configuration. Anyone who can reach the instance can read what it was told to do, which is the first step of any attack.
- Meta security researcher Summer Yue had OpenClaw delete her email in a controlled test. Not a hypothetical. An actual observed autonomous action against a real inbox.
- Researchers cataloged 506 prompt injection attempts targeting agents that read content from Moltbook, a social network populated by OpenClaw instances. The attack surface is not theoretical. It is being probed daily by opportunistic and skilled attackers alike.
- Community-created skills have repeatedly contained malware. Researchers observed that malicious skills often reappear under new names after being removed from official registries, because there is no mechanism to prevent it.
None of this means OpenClaw is unusable forever. It means OpenClaw is unusable on the machine that has your customer database, your accounting login, and your production credentials on it.
Why the risk model is different from Claude Cowork
Cowork inherits the same underlying risks that any agent inherits: prompt injection, over-broad permissions, the classic "agent does thing you did not ask for" pattern. The Cowork playbook (sandbox folder, "Act without asking" off, activity log review) applies just as much to any other agent, including OpenClaw.
But Cowork has three structural advantages OpenClaw does not.
- A single vendor owns both the product and the safety infrastructure. When Anthropic ships an update to the content classifier that catches 99 percent of prompt injection attempts, every Cowork user gets it. There is one place to file a security report and one place to patch.
- There is no plugin ecosystem in the same sense. Cowork's tools are curated. OpenClaw's skills marketplace is open, which is the whole point of an open-source project, and also the reason malware slips through.
- Cowork does not run as a background service that other software can talk to over the network. OpenClaw does. That is why 30,000 instances turned up on the public internet with weak authentication.
None of these are moral failings on OpenClaw's part. They are the trade-offs of open-source software vs. a commercial product. But if you are a business owner and someone on your team wants to install a personal AI agent, this is the trade-off you should understand before you say yes.
Should you run it at all?
Yes, actually. But not on the machine that touches anything sensitive.
The pattern for exploring OpenClaw today is the same one that used to apply to bleeding-edge software before enterprise trust could develop.
- Run it in a virtual machine, not on your daily driver.
- Give it a dedicated identity: a throwaway Gmail address, an isolated API key, no OAuth connections to your real accounts.
- Do not connect it to production databases, customer email, or accounting systems.
- Turn off any autonomous execution features until you have watched several tasks by hand and understand what it is actually doing.
- Follow the security advisories. Assume the version you installed a month ago has known holes that were fixed last week.
If that sounds like a lot of overhead just to try a piece of software, it is. That overhead is the tax the current agent ecosystem is charging for the privilege of running something that can do real work autonomously on your machine.
What to run instead if you want to actually get work done today
- Claude Cowork for desktop-assistant workflows. It is not perfect, but it is accountable to a vendor and comes with a safety posture that is actively maintained. See the Cowork playbook.
- Microsoft 365 Copilot agents for anything that lives inside the M365 stack. See Microsoft put Copilot in the box for the pricing and licensing side.
- Workflow automation with AI steps (n8n, Make, Zapier AI) for anything that crosses systems. See Beyond Cowork: three other ways to deploy agentic AI for the full breakdown.
Each of those has an accountable vendor, a published security posture, and a support channel. That is what you want on the machine you actually work on.
What OpenClaw is actually good for right now
It is a live demonstration of how autonomous local agents are going to work when the safety infrastructure catches up. Every attack researchers document against OpenClaw is one that will hit whatever commercial product does the same job in eighteen months. If you run OpenClaw in a sandbox and follow the security research, you are getting a preview of the risks your organization will inherit when a mainstream vendor ships the equivalent.
That is worth doing. It is not worth doing on your production machine.
Bottom line
OpenClaw is an important project. It is also a security surface with more than 30,000 exposed instances, an 84.6 percent system-prompt extraction rate, real observed autonomous actions gone wrong, and a plugin ecosystem researchers have documented as an active malware vector.
If a team member asks to install OpenClaw on their work laptop, the answer is no. If they want to run it in a virtual machine as a personal learning tool, that is a different conversation. If they want to deploy it against your customer data, that is a no.
For an accountable alternative that does most of what an agent should do without the current safety debt, start with Cowork. When the OpenClaw ecosystem matures, and it will, the calculation will change. For the broader executive framework on evaluating AI tools before you commit, see The AI Owner's Manual.