Running OpenClaw safely: identity, isolation, and runtime risk
ID: 019a28d9-fc14-5ac8-8066-a3993aa0dce7
STIX ID: report--019a28d9-fc14-5ac8-8066-a3993aa0dce7
Feed Name: Microsoft Security
Date Published: 2026-02-19
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
Microsoft Defender Security Research warns that self-hosted agent runtimes like OpenClaw combine untrusted code (skills) and untrusted inputs (external content) into a single execution loop with durable credentials, creating high-impact attack paths such as poisoned-skill installs and indirect prompt injection. The report recommends isolating runtimes, using dedicated least-privilege identities, monitoring for state/memory manipulation, planning for rapid rebuilds, and restricting egress and supply-chain sources. It maps these mitigations to Microsoft Security controls (Entra ID, Defender for Endpoint/XDR, App Governance, Purview) and provides Defender XDR hunting queries to discover agent deployments, detect risky skill installs, consent drift, unexpected listeners, and suspicious process spawning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
