How to Run OpenClaw Safely (and How to Know You Shouldn't)
OpenClaw is safe the way a table saw is safe: genuinely, for people who respect it. Here's the actual checklist, and the test for whether it's your tool.
Somewhere in OpenClaw's first viral month, "how do I set this up" quietly became "how do I set this up without getting owned." Fair evolution: researchers found tens of thousands of instances exposed on the open internet, and attackers flooded its skill marketplace with malicious packages.
Here's the checklist up front, because if you're going to do this, do it right: isolate the machine, lock the gateway, vet every skill, treat your API keys like cash, cap the spend, and patch like it's your job, because it now is. Below is each step in practice, followed by the more useful question, which is whether you should be doing this at all.
The OpenClaw security checklist
- Isolate it. A dedicated machine, VM, or container, not your daily laptop. An agent that can run shell commands should be running them somewhere that losing everything is an inconvenience, not a catastrophe. Your tax folder and your SSH keys should not share a filesystem with an experiment.
- Lock the gateway. The control interface must not face the open internet, and it must require authentication. Most of the exposed-instance wave was configuration left open, not exotic exploitation. If you don't know whether yours is exposed, that's an answer too.
- Vet skills like the supply-chain risk they are. Community skills are code that runs with your agent's permissions. Read them before installing, prefer well-known ones, and treat "new skill, few users, does something with credentials" as the red flag it is.
- Practice key hygiene. Scoped API keys, stored properly, rotated on a schedule, and never in a config file that a leaked backup or an exposed instance can serve to strangers. A leaked key is someone else's usage on your bill.
- Cap the spend at the provider. Set hard budget alerts and limits on the API account itself, because the software meters nothing on its own. (Why this matters is its own article.)
- Patch on someone else's schedule. Security advisories arrive when they arrive; an unpatched agent with shell access ages like milk. Subscribe to releases and treat updates as non-optional.
None of this is exotic. It's the standard operational discipline of running any internet-adjacent service, applied to one with your accounts attached.
The honest test
Read the list again and notice what it assumes: a spare machine, comfort with networking, the habit of reading code before running it, and the ongoing attention of a part-time sysadmin. If that describes you and sounds like fun, genuinely, enjoy it. OpenClaw run by a careful operator is a fine piece of software.
Frequently asked questions
- Is OpenClaw safe to use?
- In the hands of a careful operator, yes: isolated machine, authenticated gateway, vetted skills, scoped and rotated keys, provider-side spend caps, prompt patching. Its rough first weeks (tens of thousands of exposed instances, a critical RCE, malicious marketplace skills) were overwhelmingly configuration and supply-chain issues, which is exactly why the discipline matters.
- What's the single most important OpenClaw security step?
- Isolation plus a locked gateway. Most real-world damage came from instances reachable on the open internet without authentication. An agent with file and shell access must live on hardware you can afford to lose, behind a door that locks.
- I don't want to do any of this. What then?
- Use a managed platform. On myAgents the agents run sandboxed on our infrastructure with per-agent permissions, prepaid credits, and spending caps, so the security and cost discipline is built in rather than assigned to you as homework.
See the team built for you
myAgents ships ready-made teams tuned to how you work:
Try it on your own work
Hire your first team in about two minutes. $10 in free credits, no credit card required.