国产人人色I色婷婷综合久久中文字幕雪峰I奇米色777欧美一区二区I久热久热aV爽青青在线I国产av喷水I国产伦精品一区二区三区免.费I高潮av在线Iww欧美一级I91天天看I黄a在线91I九一无码中文字幕久久无码色…I丰满国产精品视频二区

Global EditionASIA 中文雙語Fran?ais
China
Home / China / Society

Guidelines released to curb OpenClaw security risks

By CUI JIA | chinadaily.com.cn | Updated: 2026-03-22 21:44
Share
Share - WeChat

To help users safely operate the open-source AI agent OpenClaw, the National Computer Network Emergency Response Coordination Center of China and the Cyberspace Security Association of China jointly released guidelines on Sunday providing security recommendations for individual users, enterprises, cloud service providers and developers.

The AI-driven automation platform — nicknamed "lobster" — is known for its ability to handle complex tasks and support a wide range of plugins. Since its release, it has triggered a global deployment surge. However, many installations are directly exposed to the public internet, making them attractive targets for cyberattacks, the National Network and Information Security Information Center under the Ministry of Public Security warned on March 13.

According to the guidelines, individual users are advised to install OpenClaw only on dedicated devices, virtual machines or containers with proper isolation. They are also urged to avoid installing it on everyday work computers or running it with administrator or superuser privileges. In addition, users should not store or process sensitive personal data within the OpenClaw environment.

The guidelines also call on cloud service providers to conduct security assessments, strengthen baseline protections for cloud hosts, integrate security safeguards, and ensure supply chain and data protection.

A cybersecurity alert issued by the center said OpenClaw faces risks in its architectural design, default settings, vulnerability management, plugin ecosystem and behavioral control mechanisms.

It noted that default configurations leave many systems exposed online, allowing access from any external IP address. Remote access does not require authentication, and sensitive data such as API keys and chat records may be stored in plaintext.

The alert also warned that OpenClaw agents may experience failures in permission controls during task execution. As a result, they could carry out unauthorized actions, ignore user instructions, or perform harmful operations such as deleting data, stealing information or taking control of user devices.

Top
BACK TO THE TOP
English
Copyright 1994 - . All rights reserved. The content (including but not limited to text, photo, multimedia information, etc) published in this site belongs to China Daily Information Co (CDIC). Without written authorization from CDIC, such content shall not be republished or used in any form. Note: Browsers with 1024*768 or higher resolution are suggested for this site.
License for publishing multimedia online 0108263

Registration Number: 130349
FOLLOW US