Security Researchers Flag Critical Vulnerabilities in OpenClaw and Agentic Frameworks

Researchers warned that agent frameworks running shell commands — including OpenClaw — are vulnerable to prompt injection and supply chain attacks via malicious "skills." Hardened forks like NanoClaw emerged, isolating agents in Docker containers.

Security Researchers Flag Critical Vulnerabilities in OpenClaw and Agentic Frameworks

Security researchers are warning that agent frameworks which can run shell commands, including OpenClaw, are exposed to a class of attacks that can turn a helpful assistant into a system-level risk. The concern is not limited to the model itself. It extends to the tools, plugins, and "skills" the agent is allowed to use on a machine.

The issue sits at the intersection of prompt injection and software supply chain security. Prompt injection is when an attacker places instructions inside content the model reads, such as a document, web page, or file, and those instructions override the user’s intent. In an agent framework, that becomes more serious because the model is not just answering in text, it may also be allowed to read files, call APIs, and execute commands.

⚡ New to this?

This is a security warning about AI agents, software that can not only generate text but also run tools and shell commands on a computer. A prompt injection is when hidden instructions inside a file or webpage trick the AI into doing something the user did not intend. The concern here is that a bad add-on, often called a skill, can act like a poisoned plugin and give attackers a path into systems that trust the agent.

🦞 OpenClaw angle

If you run OpenClaw with third-party skills, your agent can be compromised through the skill itself. The eBPF fix in v2026.4.12 addresses this, but only if you update.

According to the researchers, one of the most dangerous paths is through malicious skills. Skills are add-on modules that expand what an agent can do, often by giving it access to scripts, command-line tools, or external services. If a skill is compromised, or if a user installs a bad one from outside the trusted path, the agent can inherit that code and run it with the permissions of the agent process.

That is why shell access matters. A model that can suggest commands is one thing, but a framework that will actually execute them creates a direct route from manipulated input to system activity. In practice, that can mean reading sensitive files, modifying data, or contacting remote systems, depending on how the framework is configured.

OpenClaw was included in the warning because it fits this pattern: an agent framework built to orchestrate tools, including shell commands, and to work with third-party skills. The researchers said this makes it vulnerable to both prompt injection and supply chain attacks if those skills are not trusted and isolated properly. The same general risk applies to other agentic frameworks that expose similar capabilities.

One response has been the appearance of hardened forks such as NanoClaw, which isolate agents inside Docker containers. Docker is a container system that keeps software and its dependencies boxed off from the rest of the host machine. That kind of separation can reduce damage if an agent or skill is compromised, because the attacker is no longer sitting directly on the main system.

Container isolation is not a perfect fix, but it changes the default risk profile. Instead of letting a model operate freely on the host, the framework runs in a narrower sandbox with controlled access to files, tools, and network resources. For security teams, that is a familiar pattern, since isolation has long been used to contain untrusted workloads.

The broader problem is that agent frameworks are being asked to do more than chat. They are increasingly acting like automated operators, and operators need permissions. Once an AI system can read untrusted content and then execute actions, the security model has to account for both malicious instructions and malicious add-ons.

Researchers say that is exactly where many current agent stacks remain exposed, especially when third-party skills are allowed without strong validation or containment. The latest warning puts OpenClaw and similar frameworks under a spotlight at a time when agent automation is moving from demos into real operational use.

Source: devFlokers ↗

More from Security News