Be Very Careful with AI Agents!

AI agents—software that can take actions on your behalf using artificial intelligence—are having a moment. The appeal is obvious: imagine a robot butler that triages your inbox, manages your calendar, and handles tedious tasks while you focus on more important work.

That’s the promise driving the recent surge in popularity of OpenClaw (formerly known as Clawdbot and Moltbot), which is now all the rage in tech circles. Token Security found that at least one person is using it at nearly a quarter of its enterprise customers, mostly running from personal accounts. That’s a shadow IT nightmare—employees connecting work email and Slack to an unsanctioned tool that IT doesn’t know about and can’t monitor. Whether you’re an individual tempted by OpenClaw’s promise or a manager wondering what your users are up to, you need to understand the risks these AI agents pose.

OpenClaw is an AI agent built around “skills”—installable plugins that let it integrate with your messaging apps, email, calendar, and more. You communicate with OpenClaw via Messages, Slack, WhatsApp, and similar apps. Because it’s open source, you’ll need to provide your own API keys for AI services like OpenAI or Anthropic, which means ongoing costs that can add up quickly—people have reported spending $10–$25 per day.

The more serious problem? Security researchers have discovered serious vulnerabilities, including misconfigured instances exposed to the internet that leak credentials, API keys, and private messages, and a supply chain vulnerability where malicious skills uploaded to the ClawdHub library can execute arbitrary commands on users’ systems. Even beyond specific bugs, OpenClaw’s fundamental design encourages users to grant broad access to sensitive accounts.

Why AI Agents Are Risky

Security concerns aren’t unique to OpenClaw—they apply to any AI agent that acts on a user’s behalf. Here’s what’s at stake:

  • Credential exposure: For an AI agent to send emails, manage your calendar, or post to Slack, it needs your authentication tokens or login credentials. If the agent software stores these credentials insecurely, or an attacker gains control, they could be exposed.
  • Prompt injection: AI agents work by following instructions, but they can’t easily distinguish between prompts and data in the content they use. A class of attacks called “prompt injections” trick AI systems by hiding malicious content in emails, websites, or documents that will be processed. An attacker could embed instructions in an email that would cause your agent to search for and forward email messages containing passwords or financial data, follow links to malware sites, or take other harmful actions. There is currently no foolproof defense against this class of attack.
  • Data exfiltration: An AI agent with access to your email and your computer’s filesystem could be manipulated to extract information from elsewhere on your computer—financial data, customer lists, or personal details—and send it to an attacker.
  • Unvetted extensions: OpenClaw and similar AI agents let users install “skills” or plugins to extend functionality. Libraries that allow users to share custom skills often have minimal or no security vetting, making it easy for attackers to submit poisoned skills. Installing such a skill could grant malicious code access to everything your agent can touch.
  • Exposed control interfaces: Security researchers found OpenClaw control servers exposed on the Internet, potentially leaking API keys, VPN credentials, and conversation histories. This risk is unique to OpenClaw at the moment, but future AI agents may suffer from similar vulnerabilities, particularly as they’re adopted by less technically savvy users.

How to Reduce Your Risk

We’ll come right out and say it: we strongly recommend against installing OpenClaw or other AI agents on your Mac. In a year or so, Apple may have updated Siri to provide many of these capabilities with significantly stronger privacy and security. But for now, just say no.

If you decide to use AI agents despite these risks, here are practical steps to protect yourself:

  • Use dedicated accounts: When possible, create separate accounts specifically for agent use rather than linking your primary personal or work accounts.
  • Limit permissions: Grant the agent access only to accounts it absolutely needs. If you only want help with your calendar, don’t also connect your email and messaging services.
  • Avoid connecting sensitive services: Never connect anything involving money, healthcare, or confidential business information. The liability is too high if something goes wrong.
  • Review agent actions: If the platform offers logs or activity feeds, check them regularly. Look for unexpected messages sent, files accessed, or connections made.
  • Vet extensions carefully: Don’t install skills or plugins from unknown sources, and even with known libraries, look for evidence of others using and reviewing the skills. Treat skills like any other software you’d install on your computer.
  • Keep software updated: Security patches for OpenClaw and similar tools address known vulnerabilities. If you’re running an agent, keep it up to date.
  • Run agents in isolated environments: Technical users should consider running agents in sandboxed environments or virtual machines to limit potential damage.

If you run a business, you should assume that some employees have already installed OpenClaw or will soon, and may have connected their work email and Slack accounts without realizing the associated risks. Here’s what you can do:

  • Educate before it’s a problem: Proactively explain the risks to employees. People are more receptive before they’ve already invested time setting something up.
  • Update acceptable use policies: Make clear that connecting work accounts to unsanctioned AI agents is prohibited, and explain why.
  • Offer sanctioned alternatives: If employees want AI assistance, point them toward safer options that don’t require handing over credentials to sensitive accounts.

What About Claude Cowork and OpenAI Codex?

Not all AI agent platforms carry the same level of risk. Anthropic’s Claude Cowork and OpenAI’s Codex take a different architectural approach from OpenClaw. Rather than requesting authentication tokens for your email, messaging, and other personal services, they operate within their own controlled, sandboxed environments. These systems work primarily with files, code, and data you explicitly place into their workspace, which substantially limits the fallout from an attacker gaining some level of control.

This containment approach reduces risk, but does not eliminate it. Prompt injection remains a concern whenever an AI system processes untrusted content, even inside a sandbox. An AI agent analyzing a malicious document could still be manipulated into taking unintended actions within its allowed environment. Similarly, any code generated by these systems—particularly code that touches the network or executes system commands—should be reviewed carefully to make sure it hasn’t been compromised by prompt injection.

The key distinction is scope. Claude Cowork and Codex are designed to operate within a defined workspace, whereas tools like OpenClaw require standing access to your most sensitive accounts. From a security perspective, a compromised sandbox is a recoverable incident; a compromised email or messaging account may not be.

The Bottom Line

AI agents promise a lot and may provide genuine convenience, but at a cost beyond just paying for API tokens. Before you or anyone in your organization connects an AI agent to sensitive accounts, consider: What’s the worst that could happen if this system were compromised by an attacker? If the answer involves passwords being stolen, private email being exposed, or photos being posted to social media without your knowledge, proceed with extreme caution. If you can imagine a way financial accounts could be accessed or business data stolen, don’t proceed at all.

(Featured image by iStock.com/Thinkhubstudio)


Social Media: AI agents like OpenClaw promise to automate tedious tasks, but recent security vulnerabilities highlight the dangers of using them. Learn the risks and how to protect yourself—and your organization—if you choose to use an agent.

Similar Posts

  • Macbooks and Macbook Air Upgraded

    Apple announced some changes to the 12-inch MacBook and 13-inch MacBook Air this week. Let’s talk about the MacBook Air first. Apple discontinued the 13-inch MacBook Air models that had 4GB of RAM and made them sport 8GB. There were no other changes to this model but the additional RAM comes at no additional cost as Apple doubled the RAM but kept the price the same at $999 for the 128GB SSD unit and $1299 for the 256GB SSD.

    With just this minor update to the MacBook Air we can speculate that perhaps this unit is on its way out within the next year. The MacBook Air does not have the Retina display nor does it support the latest in Intel mobile processors. On the other hand, it is Apple’s best selling laptop.

    The changes to the MacBook were more significant. They added a Rose Gold (er…pink) color which might actually be a nice option for some. More importantly, Apple went to the new sixth-generation dual-core Intel Core M processors which run at clock speeds up to 1.3 gigahertz, with Turbo Boost up to 3.1 gigahertz. The revamped notebooks also feature faster 1866 megahertz memory.

    This new processor yields increases in performance from 15-20% in initial testing. With the Intel HD Graphics 515, the new MacBook has about 25 percent faster graphics performance. Speed has also been enhance with new, faster PCIe-based flash storage.

    The lower power requirements and a slightly larger battery has also improved battery life, with the Apple claiming the new MacBook offers up to 10 hours of wireless surfing and up to 11 hours of movie watching.

    While some were expecting additional ports or an improved FaceTime camera, these features did not make the cut.

    We should have all the models in stock next week as well as some great deals on the newly discontinued models.

  • Expand your mind…er..text

    Speed Up Your Fingers with Text Expansion

    With all the advances in computing and communications, it’s amazing that–after nearly 150 years!–we still use the keyboard layout from the world’s first practical typewriter for entering text into our Macs, iPhones, and iPads. Sure there are some improving dictation solutions out there but typing is by far how we input text. But we have not gotten that much better as typists, nor do we enjoy typing more–if anything, we increasingly abbreviate to avoid typing, hence “LOL, BRB, etc.” Text messaging aside, wouldn’t it be nice to be able to type less without compromising meaning or making your text look like it was composed by a trained monkey? Thanks to text expansion features built into OS X and iOS, and extended with third-party utilities, you can.

    For basic text expansion capabilities in OS X, look in System Preferences > Keyboard > Text, and in iOS 9, go to Settings > General > Keyboard > Text Replacement. For both, you can enter a phrase, and a shortcut that expands into that phrase when typed and followed by a space or punctuation character. (Tip: If text expansion doesn’t work in a Mac app like Mail or Safari, make sure Edit > Substitutions > Text Replacement is selected.)

    If you’re signed into the same iCloud account on both your Mac and your iPhone, for instance, the text expansions sync between them automatically. So, you can type “smh” and tap the Space bar to get “Shaking my head!” typed out for you, regardless of what device you’re using. (Another tip: don’t create abbreviations that you will also want to type normally. It might seem like a good idea to use “np” for “No Problem,” but that will get in the way of talking about Nurse Practitioners.)

    With such a useful feature built into OS X and iOS, why would you want to spend money on a third-party utility, like “**TextExpander**”:https://smilesoftware.com/textexpander (Mac and iOS), “**Typinator**”:http://www.ergonis.com/products/typinator/ (Mac), or “**TypeIt4Me**”:http://www.ettoresoftware.com/products/typeit4me/. Unfortunately, OS X’s text expansion feature doesn’t work in all apps (it likely won’t work if the app lacks the Edit > Substitutions > Text Replacement menu command). The interface for creating new substitutions is cramped and hard to work with, you can’t configure the trigger characters that cause abbreviations to expand, and you can’t include text with styles, variable text like the date, or even graphics.

    That’s where text expansion utilities shine. They can include styled text and graphics in expansions, insert the current date and time, respect case when expanding abbreviations, include the contents of the clipboard in expanded text, automatically fix common typos, create fill-in-the-blanks snippets that you customize on each expansion, and much more.

    Here are some ideas for the kinds of things you might want to turn over to your computer for typing:
    Long or complex words or phrases, such as scientific names. Aedes aegypti, anyone?

    *Your address, phone number, and email address. One of my favorites is “@d” which inserts my email address. I get real tired of typing email address, phone numbers, etc. Text expansion speeds that up!

    *Boilerplate text for common email replies.

    *The current date and/or time.

    *Special characters, so blb could expand to the British pound symbol £.

    *Unix commands for Terminal, such as using ssh to log in to a remote computer.

    I am sure you can come up with dozens that might work for you and speed up your typing. So think about what bit of text you might want expand automatically and give text expansion a try today!