OpenClaw has access to files, commands and accounts, and it acts on your behalf. So the right security question is not “is the program safe?”, it is “what happens on the worst day, and how much damage can it do?”. You control the answer with four decisions: a user of its own, with no permanent root; minimum permissions; a server that holds nothing else important; and spending limits at the model provider.
This holds for any agent that executes things, not just this one. There is no way to guarantee that an AI model is always right, or that it ignores bad instructions hidden in a text. That is why you limit its reach instead of trusting it.
What it can reach
| Reach |
The risk |
The limit to set |
| Files on the server |
Reading secrets, deleting or changing data |
Run it as a user with no access to your other applications and files |
| Commands |
Running something destructive, by mistake or by malicious instruction |
No permanent root. No free sudo for that user. |
| Accounts and keys |
Spending money or sending on your behalf |
Keys with only the permissions needed, and a spending limit at the provider |
| Messaging channels |
Anyone who writes to it can give it orders |
Authorised accounts only. See connecting a channel. |
| Network |
Ports open to the internet |
Only the ones you need, with the firewall on |
How to limit it, in order
| 1 |
A server just for it. Do not install it on the VPS that holds the website, the shop or the company database. A test server, easy to rebuild, is the right place to start.
|
|
| 2 |
A user of its own, no permanent root. Log in as root only to prepare things. After that, OpenClaw runs as a normal user that only sees its own folder.
|
|
| 3 |
Minimum permissions. Give it only the folders and accounts the task needs. If the documentation offers a mode that asks for confirmation before sensitive actions, use it, and remember that a confirmation only protects you if you read it.
|
|
| 4 |
Keys with limits. Create an API key just for this agent and, in the provider’s console, set a spending limit if the provider allows it. See getting a key and keeping it safe.
|
|
| 6 |
Have a way back. A snapshot before you give it new powers. See backing up a VPS.
|
|
|
Hidden instructions. If the agent reads a web page, an e-mail or a file containing text like “ignore what you were asked and do this”, it may obey. The more unknown sources it reads, the greater the risk. Do not give it access to sensitive things and to strangers’ content at the same time.
|
|
Never give the agent your control-panel password, your domain keys, your mailbox key or customer data just because it is “easier”. Whatever it reads may pass through the model provider.
|
|
Read the logs now and then. If commands show up that you did not ask for, switch the agent off, revoke the keys and restore the snapshot. See running OpenClaw day to day.
|
|
Want to be sure your VPS is closed the way it should be? Ask us for help with the server’s access and network.
Open a support ticket
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $6.59/mo (3-year plan, with coupon) See plans |