logo

Running OpenClaw safely: identity, isolation, and runtime risk

ID: 019a28d9-fc14-5ac8-8066-a3993aa0dce7

STIX ID: report--019a28d9-fc14-5ac8-8066-a3993aa0dce7

Feed Name: Microsoft Security

Date Published: 2026-02-19

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

Microsoft Defender Security Research warns that self-hosted agent runtimes like OpenClaw combine untrusted code (skills) and untrusted inputs (external content) into a single execution loop with durable credentials, creating high-impact attack paths such as poisoned-skill installs and indirect prompt injection. The report recommends isolating runtimes, using dedicated least-privilege identities, monitoring for state/memory manipulation, planning for rapid rebuilds, and restricting egress and supply-chain sources. It maps these mitigations to Microsoft Security controls (Entra ID, Defender for Endpoint/XDR, App Governance, Purview) and provides Defender XDR hunting queries to discover agent deployments, detect risky skill installs, consent drift, unexpected listeners, and suspicious process spawning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.