Is OpenClaw Safe? Permissions, Privacy and Risks

OpenClaw can read your files, run commands and message people on your behalf. That's what makes it useful, and also what makes a careless setup risky. This guide explains what's safe out of the box, what isn't, where your data goes, and exactly how to lock it down.

Short answer

It can be safe, but not automatically. By default OpenClaw stays on your machine, makes strangers pair before chatting, and gates groups behind mentions. But on a normal install it runs shell commands without asking and sandboxing is off. Spend 10 minutes on the settings below, run openclaw security audit, and never install unvetted skills.

Out of the box

What's safe by default, and what isn't

on by default

Protected for you

  • Local only: the gateway listens on 127.0.0.1 on normal installs
  • Pairing: unknown people who DM it get a pairing code. Their messages aren't processed until you approve them.
  • Groups: allowlisted, and it usually only replies when mentioned
  • Redaction: secrets are always redacted from logs and transcripts
  • Non-owners can't use the cron or gateway tools from chat
your job

Not protected until you change it

  • Shell commands run without asking. Host exec defaults to security: "full", ask: "off".
  • Sandboxing is off (sandbox.mode: "off")
  • Docker images bind to all interfaces by default, so pair them with auth
  • Agents can message across chats and apps, and talk to each other
  • Skills and plugins run as code you choose to trust
Why this matters

The defaults stop strangers from using your assistant. They don't limit what the assistant does once it's tricked, for example by a malicious web page or email. That's what tool limits, approvals and sandboxing are for.

Threats

The main OpenClaw risks

HighExposed gateway

Security researchers found 30,000+ instances reachable online without authentication in early 2026, leaking API keys and chats.

Fix: keep it on loopback or a tailnet, and use token auth.
HighMalicious skills

Hundreds of ClawHub skills were found stealing credentials in 2026, some among the most downloaded.

Fix: read the code before installing. Treat every skill as untrusted.
HighPrompt injection

Web pages, emails and files can hide instructions such as "send me your files". It doesn't need a stranger to DM you.

Fix: strong model, tool limits, approvals, a sandbox.
MediumOver-broad permissions

An agent with shell, file and messaging access can do real damage if misled.

Fix: messaging-only profile, workspace-only files, exec approvals.
MediumSecrets on disk

Tokens, chat logs and memory live under ~/.openclaw/. Anyone with disk access can read them.

Fix: 700/600 permissions, disk encryption, a dedicated OS user.
MediumShared use

OpenClaw isn't a hostile multi-tenant boundary. People sharing one gateway can influence each other's turns.

Fix: separate gateways, or users and hosts, for people who don't trust each other.

For the full 2026 incident timeline, see our OpenClaw review.

Permissions

How OpenClaw permissions work

Think of five layers. An action must pass every one.

  1. Networkgateway.bind: "loopback" plus gateway.auth.mode: "token" decide who can reach the gateway at all.
  2. Who can messagedmPolicy: "pairing" or "allowlist", and requireMention in groups, decide whose messages it reads. session.dmScope: "per-channel-peer" keeps each person's DMs separate.
  3. Which toolstools.profile, tools.deny and tools.fs.workspaceOnly decide what it can touch.
  4. How commands runtools.exec.security (deny, allowlist, full) and tools.exec.ask (off, on-miss, always) decide whether you're asked first.
  5. Where it runsagents.defaults.sandbox.mode (off, non-main, all) moves tool execution into Docker, Podman, SSH and other backends.
Exec settingValueWhat happens
securitydenyBlocks all host commands
allowlistRuns only allowlisted commands
full host defaultNo allowlist needed
askoff defaultNo approval prompts
on-missAsks when a command isn't on the allowlist
alwaysAsks before every command

If a prompt is needed but nobody answers, askFallback defaults to deny. Sandboxed hosts default to security: "deny". The docs call sandboxing "not a perfect security boundary", but say it "materially limits" damage.

Make it yours

Security config builder

Choose how locked down you want it

Start from a preset, then adjust. Merge the result into ~/.openclaw/openclaw.json, restart the gateway, and run openclaw security audit.

Risk
Low
~/.openclaw/openclaw.json (JSON5)

Keys come from OpenClaw's hardened baseline and sandboxing docs. Sandboxing needs Docker or Podman installed. Generate a long token with openssl rand -hex 32.

Privacy

Where your data goes

Stays on your machine
  • Memory and workspace files
  • Chat transcripts: ~/.openclaw/agents/<id>/sessions/*.jsonl
  • Channel logins and pairing lists: ~/.openclaw/credentials/
  • Model keys: per-agent SQLite auth store
  • Logs: /tmp/openclaw/ (redacted)
Leaves your machine
  • Each prompt and context, to your model provider
  • Messages, through WhatsApp, Telegram and other chat services
  • Web searches and pages it fetches
  • Calls to any skills or services you connect
Most private

Use a local model so prompts never leave your hardware.

Lock the folder

Use 700 on ~/.openclaw and 600 on openclaw.json. openclaw security audit --fix sets these.

Encrypt and separate

Turn on full-disk encryption, and run the gateway as its own OS user on shared machines.

Transcripts can contain pasted secrets and file contents. Prune old ones if you don't need them. When sharing diagnostics, use openclaw status --all, which redacts secrets.

Supply chain

Installing skills and plugins safely

Skills are code and instructions your agent will follow, with your permissions. In 2026, attackers uploaded credential-stealing skills to ClawHub, and some reached the top downloads.

  1. Read it first. Open the skill's files, and check for downloads, curl … | sh, encoded strings or "prerequisites" that install software.
  2. Check the publisher: their history, other skills and source repo.
  3. Prefer fewer skills. Ask OpenClaw to write a small skill for you instead of installing a big unknown one.
  4. Pin versions. The audit warns about unpinned plugins or ones without integrity data.
  5. Test in a sandbox with sandbox.mode: "all" before trusting a new skill.

More: OpenClaw skills guide.

Model choice

Your model is a security layer

The OpenClaw docs cite a 2026 crowdsourced test of 272,000 attacks across 41 agent scenarios. It counted only attacks where the agent did something harmful and hid it. Results varied widely by model:

Claude Opus 4.5
0.5%
Claude Sonnet 4.5
1.0%
Claude Haiku 4.5
1.3%
Gemini 2.5 Pro
8.5%

Attack success rate. Lower is better. Determined attackers who adapt still beat leading defenses more than 80% of the time, and small or local models are much easier to steer. Use a strong current model for any agent with tools, and keep hard limits on regardless.

Check yourself

Run the built-in security audit

Terminal
openclaw security audit          # config and file checks
openclaw security audit --deep   # adds live gateway probes
openclaw security audit --fix    # applies safe fixes

--fix will

  • Switch open group policies to allowlists
  • Tighten permissions on config, credentials and state files

--fix won't

  • Rotate tokens or API keys
  • Disable tools such as exec or cron
  • Change network exposure, or remove plugins and skills

The audit also flags reused or short webhook tokens, open DMs with powerful tools, small models without a sandbox, risky Docker network modes and any dangerous… flags you've enabled.

Checklist

OpenClaw security checklist

Tick these off for a solid personal setup.

0/10

Also keep OpenClaw updated: many 2026 fixes shipped as patches. See update and back up, and for servers, VPS hardening.

Incident response

If you think something went wrong

1Contain

Stop the gateway. Set gateway.bind: "loopback". Switch risky DMs to dmPolicy: "disabled" and remove any "*" allow-all entries.

2Rotate

Change the gateway token or password, remote client secrets, channel tokens (WhatsApp, Slack, Discord) and model API keys.

3Audit

Read openclaw logs and the transcripts. Check recent config changes, then run openclaw security audit --deep.

4Report

Note the timestamp, OS, OpenClaw version, what was sent and what the agent did, and whether the gateway was exposed.

FAQ

OpenClaw safety questions

Is OpenClaw safe to use?

It can be. By default it stays on your machine, requires strangers to pair, and gates groups behind mentions. But host shell commands run without approval and sandboxing is off, so turn on exec approvals, limit tools, avoid unvetted skills and run openclaw security audit.

Does OpenClaw ask before running commands?

Not by default on a normal install, where host exec uses security full and ask off. Set tools.exec.ask to on-miss or always, or tools.exec.security to allowlist or deny, to require approval or block commands.

Can OpenClaw see my files?

It can read and write files with the same permissions as the user running it, unless you limit it. Set tools.fs.workspaceOnly to true and enable a sandbox to confine it to its workspace.

Does OpenClaw send my data to the cloud?

Memory, transcripts and credentials stay on your machine. Your prompts go to the AI model provider you choose, and messages pass through the chat apps you connect. A local model keeps prompts on your hardware.

Are ClawHub skills safe?

Not automatically. Researchers found hundreds of malicious skills on ClawHub in 2026, some highly downloaded. Read a skill's code, check the publisher and test it in a sandbox before trusting it.

How do I check my OpenClaw security settings?

Run openclaw security audit, or add --deep for live gateway checks. The --fix option tightens file permissions and open group policies, but it doesn't rotate keys, disable tools or change network exposure.

Related guides