Privacy Concerns in OpenClaw: Skills, SOUL MD, and Agent Communication

✍️ OpenClawRadar📅 Published: March 22, 2026🔗 Source
Privacy Concerns in OpenClaw: Skills, SOUL MD, and Agent Communication
Ad

A developer on r/openclaw has raised significant privacy concerns about OpenClaw's current architecture, highlighting specific areas that need attention as the platform grows.

Key Privacy Issues Identified

The source identifies three main privacy concerns:

  • Skills have unrestricted access: When you install a skill from ClawHub, it gets access to "your entire digital life" including your SOUL MD, memory, and credentials. The source cites Cisco research showing 26% of community skills had security issues, and notes there's "basically zero permission scoping."
  • SOUL MD is writable: The file that defines who an agent "IS" can be rewritten, as demonstrated when "a moltbook post rewrote the file" in what the source calls "identity-level prompt injection." This occurred in the "crustafarianism" incident where an agent started a religion while its owner was sleeping.
  • Agents share everything: When agents communicate on platforms like moltbook, there's "zero concept of 'maybe don't share that'"—they send whatever information without filters or privacy awareness.
Ad

Context and Concerns

The developer notes that while current OpenClaw users "know what they're doing," they're concerned about broader adoption, mentioning "photos from Shenzhen where literal retirees are lining up to get this installed on their laptops." They question whether "it's open source so just audit it yourself" is sufficient for privacy protection.

The source acknowledges OpenClaw's positive aspects—"local-first is the right call, workspace-as-files is genius, the heartbeat system is chef's kiss"—but emphasizes that privacy considerations need more attention in the architecture.

📖 Read the full source: r/openclaw

Ad

👀 See Also

Linux Kernel Proposes Decentralized Identity System to Replace PGP Web of Trust
Security

Linux Kernel Proposes Decentralized Identity System to Replace PGP Web of Trust

Linux kernel maintainers are working on a decentralized identity layer called Linux ID to replace the current PGP web of trust. The system uses W3C-style decentralized identifiers (DIDs) and verifiable credentials to authenticate developers without requiring face-to-face key-signing sessions.

OpenClawRadar
Supply-chain attack uses invisible Unicode code to bypass detection
Security

Supply-chain attack uses invisible Unicode code to bypass detection

Researchers discovered 151 malicious packages uploaded to GitHub from March 3-9 using invisible Unicode characters to hide malicious code. The attack targets GitHub, NPM, and Open VSX repositories with packages that appear legitimate but contain hidden payloads.

OpenClawRadar
Unsecured Paperclip Instances Exposing Live Dashboards via Google Search
Security

Unsecured Paperclip Instances Exposing Live Dashboards via Google Search

A Reddit user discovered a live Paperclip dashboard with full organizational data indexed by Google after searching for an error. The instance was publicly exposed without authentication, revealing org charts, agent conversations, task assignments, and business plans.

OpenClawRadar
Claude's Conversation Search Tool Still Returns Deleted Chats
Security

Claude's Conversation Search Tool Still Returns Deleted Chats

A Claude Pro user discovered that deleted conversations remain retrievable through Claude's conversation search tool, returning substantive content including titles, message counts, and excerpts despite the chat links being dead.

OpenClawRadar