What's safe by default, and what isn't
Protected for you
- Local only: the gateway listens on
127.0.0.1on normal installs - Pairing: unknown people who DM it get a pairing code. Their messages aren't processed until you approve them.
- Groups: allowlisted, and it usually only replies when mentioned
- Redaction: secrets are always redacted from logs and transcripts
- Non-owners can't use the
cronorgatewaytools from chat
Not protected until you change it
- Shell commands run without asking. Host exec defaults to
security: "full",ask: "off". - Sandboxing is off (
sandbox.mode: "off") - Docker images bind to all interfaces by default, so pair them with auth
- Agents can message across chats and apps, and talk to each other
- Skills and plugins run as code you choose to trust
The defaults stop strangers from using your assistant. They don't limit what the assistant does once it's tricked, for example by a malicious web page or email. That's what tool limits, approvals and sandboxing are for.
The main OpenClaw risks
Security researchers found 30,000+ instances reachable online without authentication in early 2026, leaking API keys and chats.
Fix: keep it on loopback or a tailnet, and use token auth.Hundreds of ClawHub skills were found stealing credentials in 2026, some among the most downloaded.
Fix: read the code before installing. Treat every skill as untrusted.Web pages, emails and files can hide instructions such as "send me your files". It doesn't need a stranger to DM you.
Fix: strong model, tool limits, approvals, a sandbox.An agent with shell, file and messaging access can do real damage if misled.
Fix: messaging-only profile, workspace-only files, exec approvals.Tokens, chat logs and memory live under ~/.openclaw/. Anyone with disk access can read them.
700/600 permissions, disk encryption, a dedicated OS user.OpenClaw isn't a hostile multi-tenant boundary. People sharing one gateway can influence each other's turns.
Fix: separate gateways, or users and hosts, for people who don't trust each other.For the full 2026 incident timeline, see our OpenClaw review.
How OpenClaw permissions work
Think of five layers. An action must pass every one.
- Network
gateway.bind: "loopback"plusgateway.auth.mode: "token"decide who can reach the gateway at all. - Who can message
dmPolicy: "pairing"or"allowlist", andrequireMentionin groups, decide whose messages it reads.session.dmScope: "per-channel-peer"keeps each person's DMs separate. - Which tools
tools.profile,tools.denyandtools.fs.workspaceOnlydecide what it can touch. - How commands run
tools.exec.security(deny,allowlist,full) andtools.exec.ask(off,on-miss,always) decide whether you're asked first. - Where it runs
agents.defaults.sandbox.mode(off,non-main,all) moves tool execution into Docker, Podman, SSH and other backends.
| Exec setting | Value | What happens |
|---|---|---|
security | deny | Blocks all host commands |
allowlist | Runs only allowlisted commands | |
full host default | No allowlist needed | |
ask | off default | No approval prompts |
on-miss | Asks when a command isn't on the allowlist | |
always | Asks before every command |
If a prompt is needed but nobody answers, askFallback defaults to deny. Sandboxed hosts default to security: "deny". The docs call sandboxing "not a perfect security boundary", but say it "materially limits" damage.
Security config builder
Choose how locked down you want it
Start from a preset, then adjust. Merge the result into ~/.openclaw/openclaw.json, restart the gateway, and run openclaw security audit.
Keys come from OpenClaw's hardened baseline and sandboxing docs. Sandboxing needs Docker or Podman installed. Generate a long token with openssl rand -hex 32.
Where your data goes
- Memory and workspace files
- Chat transcripts:
~/.openclaw/agents/<id>/sessions/*.jsonl - Channel logins and pairing lists:
~/.openclaw/credentials/ - Model keys: per-agent SQLite auth store
- Logs:
/tmp/openclaw/(redacted)
- Each prompt and context, to your model provider
- Messages, through WhatsApp, Telegram and other chat services
- Web searches and pages it fetches
- Calls to any skills or services you connect
Use a local model so prompts never leave your hardware.
Use 700 on ~/.openclaw and 600 on openclaw.json. openclaw security audit --fix sets these.
Turn on full-disk encryption, and run the gateway as its own OS user on shared machines.
Transcripts can contain pasted secrets and file contents. Prune old ones if you don't need them. When sharing diagnostics, use openclaw status --all, which redacts secrets.
Installing skills and plugins safely
Skills are code and instructions your agent will follow, with your permissions. In 2026, attackers uploaded credential-stealing skills to ClawHub, and some reached the top downloads.
- Read it first. Open the skill's files, and check for downloads,
curl … | sh, encoded strings or "prerequisites" that install software. - Check the publisher: their history, other skills and source repo.
- Prefer fewer skills. Ask OpenClaw to write a small skill for you instead of installing a big unknown one.
- Pin versions. The audit warns about unpinned plugins or ones without integrity data.
- Test in a sandbox with
sandbox.mode: "all"before trusting a new skill.
More: OpenClaw skills guide.
Your model is a security layer
The OpenClaw docs cite a 2026 crowdsourced test of 272,000 attacks across 41 agent scenarios. It counted only attacks where the agent did something harmful and hid it. Results varied widely by model:
Attack success rate. Lower is better. Determined attackers who adapt still beat leading defenses more than 80% of the time, and small or local models are much easier to steer. Use a strong current model for any agent with tools, and keep hard limits on regardless.
Run the built-in security audit
openclaw security audit # config and file checks
openclaw security audit --deep # adds live gateway probes
openclaw security audit --fix # applies safe fixes--fix will
- Switch open group policies to allowlists
- Tighten permissions on config, credentials and state files
--fix won't
- Rotate tokens or API keys
- Disable tools such as
execorcron - Change network exposure, or remove plugins and skills
The audit also flags reused or short webhook tokens, open DMs with powerful tools, small models without a sandbox, risky Docker network modes and any dangerous… flags you've enabled.
OpenClaw security checklist
Tick these off for a solid personal setup.
Also keep OpenClaw updated: many 2026 fixes shipped as patches. See update and back up, and for servers, VPS hardening.
If you think something went wrong
Stop the gateway. Set gateway.bind: "loopback". Switch risky DMs to dmPolicy: "disabled" and remove any "*" allow-all entries.
Change the gateway token or password, remote client secrets, channel tokens (WhatsApp, Slack, Discord) and model API keys.
Read openclaw logs and the transcripts. Check recent config changes, then run openclaw security audit --deep.
Note the timestamp, OS, OpenClaw version, what was sent and what the agent did, and whether the gateway was exposed.
OpenClaw safety questions
Is OpenClaw safe to use?
It can be. By default it stays on your machine, requires strangers to pair, and gates groups behind mentions. But host shell commands run without approval and sandboxing is off, so turn on exec approvals, limit tools, avoid unvetted skills and run openclaw security audit.
Does OpenClaw ask before running commands?
Not by default on a normal install, where host exec uses security full and ask off. Set tools.exec.ask to on-miss or always, or tools.exec.security to allowlist or deny, to require approval or block commands.
Can OpenClaw see my files?
It can read and write files with the same permissions as the user running it, unless you limit it. Set tools.fs.workspaceOnly to true and enable a sandbox to confine it to its workspace.
Does OpenClaw send my data to the cloud?
Memory, transcripts and credentials stay on your machine. Your prompts go to the AI model provider you choose, and messages pass through the chat apps you connect. A local model keeps prompts on your hardware.
Are ClawHub skills safe?
Not automatically. Researchers found hundreds of malicious skills on ClawHub in 2026, some highly downloaded. Read a skill's code, check the publisher and test it in a sandbox before trusting it.
How do I check my OpenClaw security settings?
Run openclaw security audit, or add --deep for live gateway checks. The --fix option tightens file permissions and open group policies, but it doesn't rotate keys, disable tools or change network exposure.