zlacker

[return to "OpenClaw – Moltbot Renamed Again"]
1. eric-b+qh[view] [source] 2026-01-30 08:21:41
>>ed+(OP)
Before using make sure you read this entirely and understand it: https://docs.openclaw.ai/gateway/security Most important sentence: "Note: sandboxing is opt-in. If sandbox mode is off" Don't do that, turn sandbox on immediately. Otherwise you are just installing an LLM controlled RCE.

There are still improvements to be made to the security aspects yet BIG KUDOS for working so hard on it at this stage and documenting it extensively!! I've explored Cursor security docs (with a big s cause it's so scattered) and it was nothing as good.

◧◩
2. TZubir+0n[view] [source] 2026-01-30 09:15:09
>>eric-b+qh
It's typically used with external sandboxes.

I wouldn't trust its internal sandbox anyway, now that would be a mistake

◧◩◪
3. jychan+Wr[view] [source] 2026-01-30 09:57:55
>>TZubir+0n
Yeah, keep it in a VM or a box you don't care about. If you're running it on your primary machine, you're a dumbass even if you turn on sandbox mode.
◧◩◪◨
4. windex+9X[view] [source] 2026-01-30 13:59:47
>>jychan+Wr
It's really easy to run this in a container. The upside is you get a lot of protection included. The downside is you're rebuilding the container to add binaries. The latter seems like a fair tradeoff.

What I'll say about OpenClaw is that it truly feels vibe coded, I say that in a negative context. It just doesn't feel well put together like OpenCode does. And it definitely doesn't handle context overruns as well. Ultimately I think the agent implementation in n8n is better done and provides far more safeguards and extensibility. But I get it - OpenClaw is supposed to run on your machine. For me, though, if I have an assistant/agent I want it to just live in those chat apps. At that rate it's running in a container on a VPS or LXC in my home lab. This is where a powerful-enough local machine does make sense and I can see why folks were buying Mac Minis for this. But, given the quality of the project, again in my opinion, it's nothing spectacular in terms of what it can do at this point. And in some cases it's more clunky given its UI compared to other options that exist which provide the same functionality.

◧◩◪◨⬒
5. jdkoec+xz1[view] [source] 2026-01-30 16:59:19
>>windex+9X
It is completely vibe coded. The author himself says he doesn't check the code.

https://x.com/Hesamation/status/2016712942545240203

Can't believe people are giving it full access to their MacOS user session. It's a giant vulnerability waiting to happen.

Sending an email with prompt injection is all it takes.

https://x.com/Mkukkk/status/2015951362270310879

[go to top]