Settings

Theme

OpenClaw security assessment [pdf]

zeroleaks.ai

61 points by nreece 2 months ago · 20 comments

Reader

simonw 2 months ago

Almost all of this report is about leaking system prompts.

The OpenClaw system prompt has no measures in it at all to prevent leaking, because trying to protect your system prompt is almost entirely a waste of time and actually makes your product less useful.

As a result, I do not think this is a credible report.

Here's the system prompt right now: https://github.com/openclaw/openclaw/blob/b4e2e746b32f70f8fb...

DeepYogurt 2 months ago

Zeroleaks.ai is a 13 day old registration. Cool.

https://whois.domaintools.com/zeroleaks.ai

rodrigosetti 2 months ago

It's a moltbook agent tasked to get HN attention

alan_sass 2 months ago

Is this a CC generated .md report formatted as a .pdf? Looks familiar.

jonrcooper 2 months ago

Zero mention of specific models that are being compromised makes it hard to take the numbers in this report seriously.

I do understand there's a lot of people running openclaw that don't really understand it and know what models are actually running. But we've known for a while that there are tons of older models that are pretty vulnerable, and you can hook up any model to OpenClaw, so, this data is not really that useful. Even though I totally agree that there are plenty of security risks here

  • adam_arthur 2 months ago

    Relying on the model for security is not security at all.

    No amount of hardening or fine-tuning will make them immune to takeover via untrusted context

K0IN 2 months ago

Can someone give me context on why leaking the system prompt of a open source tool, I run on my machine is a problem?

  • ottah 2 months ago

    Only if you write a custom prompt with information you don't want to disclose.

bhewes 2 months ago

Ha this moltbook gone crazy.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection