OpenClaw Security: The Hardened Baseline You Should Start With

✍️ OpenClawRadar📅 Published: June 27, 2026🔗 Source
OpenClaw Security: The Hardened Baseline You Should Start With
Ad

Self-hosting OpenClaw does not mean it's self-securing. A post on r/openclaw highlights that the harder part isn't getting the bot running—it's deciding what the bot is allowed to do, who can reach it, and how much damage a bad message can cause. The post walks through OpenClaw's documented hardened baseline config, which starts closed and widens later.

Gateway: Local-Only First

The most common mistake is exposing the Gateway. The hardened baseline requires:

  • gateway.mode: "local"
  • gateway.bind: "loopback"
  • gateway.auth.mode: "token"

Expose later only when you understand the boundary you're widening.

DM Session Isolation

If multiple people can DM the bot, you need session isolation to prevent context bleed. The hardened baseline uses session.dmScope: "per-channel-peer". The rule: never combine shared DMs with broad tool access.

Tools Blast Radius

Most people think about who can message the bot before considering what authority a message inherits. The hardened baseline:

  • tools.profile: "messaging"
  • Denies group:automation, group:runtime, group:fs
  • Denies sessions_spawn and sessions_send
  • exec.security: "deny" and exec.ask: "always"
  • elevated.enabled: false

Start from denial, then re-enable the minimum you can justify.

Ad

Groups: Mention-Gated

Groups should be opt-in and mention-triggered unless you have a strong reason to loosen. The baseline uses requireMention: true for all groups.

Practical Starting Config

{
  "gateway": {
    "mode": "local",
    "bind": "loopback",
    "auth": {
      "mode": "token",
      "token": "replace-with-long-random-token"
    }
  },
  "session": {
    "dmScope": "per-channel-peer"
  },
  "tools": {
    "profile": "messaging",
    "deny": [
      "group:automation",
      "group:runtime",
      "group:fs",
      "sessions_spawn",
      "sessions_send"
    ],
    "fs": {
      "workspaceOnly": true
    },
    "exec": {
      "security": "deny",
      "ask": "always"
    },
    "elevated": {
      "enabled": false
    }
  },
  "channels": {
    "whatsapp": {
      "dmPolicy": "pairing",
      "groups": {
        "*": {
          "requireMention": true
        }
      }
    }
  }
}

Four Questions Before Widening

Before opening anything, ask:

  • Can the Gateway be reached from more places than needed?
  • Can one person's DM context leak into another's session?
  • Can an ordinary message inherit tool authority broader than intended?
  • Can a room trigger the bot too easily?

If yes, the fix is config hardening, not prompt engineering. OpenClaw gives you the surfaces—use them.

📖 Read the full source: r/openclaw

Ad

👀 See Also

OpenClaw's 'Allow Always' Feature Security Flaws and Safer Alternatives
Security

OpenClaw's 'Allow Always' Feature Security Flaws and Safer Alternatives

OpenClaw's 'allow always' approval feature has been the subject of two CVEs this month, allowing unauthorized command execution through wrapper command binding and shell line-continuation bypasses. The deeper issue is how the feature trains users to stop paying attention to security prompts.

OpenClawRadar
ClawCare: Security Guard for AI Coding Agents After AWS Key Leak
Security

ClawCare: Security Guard for AI Coding Agents After AWS Key Leak

ClawCare is a Python tool that scans commands before execution in AI coding agents like Claude Code, blocking risky patterns like bulk environment dumps and reverse shells. It was built after a developer accidentally leaked an AWS key through an agent.

OpenClawRadar
Multi-Message Prompt Injection: The "Fictional Creature" Attack Pattern Against Claude
Security

Multi-Message Prompt Injection: The "Fictional Creature" Attack Pattern Against Claude

An attack that builds a fictional rule over three messages, then summons a ghost to activate it — each message harmless in isolation. The pattern is converging independently among attackers.

OpenClawRadar
Hackerbot-Claw: AI Bot Exploiting GitHub Actions Workflows
Security

Hackerbot-Claw: AI Bot Exploiting GitHub Actions Workflows

An AI-powered bot called hackerbot-claw executed a week-long automated attack campaign against CI/CD pipelines, achieving remote code execution in at least 4 out of 6 targets including Microsoft, DataDog, and CNCF projects. The bot used 5 different exploitation techniques and exfiltrated a GitHub token with write permissions.

OpenClawRadar