Skip to content

OpenClaw · Security

OpenClaw security for enterprises: risks and controls.

OpenClaw security in an enterprise depends less on the software than on how it is configured. An agent with broad permissions, unreviewed skills and no logging is a liability; one with least privilege, isolation, human approval and a full audit trail can be operated with confidence.

Appropia has implemented OpenClaw since February 2026 and runs dozens of agents in production for several clients. This guide collects the documented risks and the controls we apply.

Talk to our team

Why an agent is different from other software

An agent combines three things that rarely come together: it reads content you do not control (emails, documents, web pages), it holds credentials, and it can act. If an attacker gets the agent to read a malicious instruction, that instruction can be executed with the agent's permissions.

The documented risks

  • Prompt injection: hidden instructions inside an email, document or page that the model treats as legitimate commands. It cannot be fully eliminated; it is contained by limiting what the agent can do.
  • Third-party skills: Cisco's researchers tested a third-party OpenClaw skill and found it exfiltrated data and performed prompt injection without the user noticing. A skill is code and text that runs with the agent's permissions.
  • Software vulnerabilities: vulnerabilities with CVE identifiers have been published, such as CVE-2026-25253 (January 2026), which allowed session credentials to be stolen through a malicious link.
  • Defaults: according to Wikipedia, OpenClaw 2.0 (August 2026) was criticized for not encrypting data at rest and not sandboxing the agent by default. Whoever deploys it has to add those protections.

Ten controls we recommend

  • Least privilege per agent: one service account each, with access only to what its task requires. Never administrator credentials.
  • Isolation: the agent runs in a separate environment (container, machine or segmented network), away from critical systems.
  • Reviewed, pinned skills: review before installing, pin the version and avoid anonymous sources.
  • Secrets outside the agent: credentials live in a secrets manager, not in memory files or prompts.
  • Encryption at rest and in transit, including the agent's memory.
  • Human approval for sensitive actions: payments, messages to third parties, deletions and production changes.
  • A complete audit trail kept outside the agent's reach: instruction, tools used, data touched and result.
  • Limits and shutdown: cost and rate limits, plus a tested procedure to stop the agent.
  • Data and model rules: decide which data may reach an external model and which requires a local one.
  • Testing before production: prompt-injection and permission-abuse cases in a test environment.

Compliance in the US and Canada

In the United States there is no general federal privacy law; state laws such as California's CCPA, as amended by the CPRA, and sector-specific rules apply. In Canada, PIPEDA remains the federal framework for the private sector; Bill C-27, which included an AI act, died when Parliament was prorogued in January 2025. Define the audit trail and the legal basis for processing personal data before an agent touches customer or employee information. This is not legal advice.

Questions to ask any vendor

  • How are agents isolated from each other and from critical systems?
  • Who reviews skills and connectors, and how are versions pinned?
  • Where are the logs stored, and who can change them?
  • Which actions require human approval, and who gives it?
  • If an agent misbehaves, how is it stopped and investigated?

Where OpenClaw Enterprise fits

OpenClaw Enterprise, announced by the OpenClaw Foundation on September 29, 2026, targets these same problems (isolation, fine-grained permissions, auditing), but it is positioned for pilot workloads and its security documentation is still to be published. We evaluate it carefully, in separate environments.

Frequently asked questions

Is OpenClaw safe for enterprise use?+

It can be, when it is configured with least privilege, isolation, reviewed skills, human approval and a full audit trail. Without those controls, the risk is high.

Can prompt injection be eliminated?+

Not completely. It is contained by limiting what the agent can do, so that a malicious instruction has little reach.

Are community skills trustworthy?+

Not by default. Review them and pin their versions before you use them.

Where can I find a complete control list?+

In our public AgenticOS Security Framework: seven principles, eight threats, a reference architecture, 25 controls and three maturity levels.

Keep reading

Sources

Information as of October 5, 2026.

Talk to our team

Want us to review your OpenClaw deployment?

WhatsApp
WhatsAppTalk to us