Microsoft security researchers have issued a warning regarding the use of OpenClaw, an AI agent runtime, on standard personal or enterprise workstations. Researchers say the runtime's method of blending untrusted instructions with executable code while using valid credentials creates significant security vulnerabilities that traditional desktop environments are not equipped to handle, Tech Radar reports.OpenClaw is designed to perform tasks by granting it broad access to software, including online services, email, login tokens, and local files. It can install external skills, process unpredictable input, and maintain persistent tokens across sessions, allowing it to operate without constant re-authentication. This combination of capabilities, especially the ability to install third-party skills and process potentially manipulated instructions, poses a risk. Unlike conventional software, OpenClaw can alter its own working state over time, potentially leading to credential exposure, data leakage, or subtle, persistent configuration changes through normal API calls using legitimate permissions.The implications of running OpenClaw on standard workstations extend to a broader discussion about the security of AI agent runtimes. Microsoft recommends strict isolation for any organization testing OpenClaw, suggesting dedicated virtual machines or separate devices with limited, purpose-built credentials.Source: Tech Radar
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



