Clawdbot AI security risks you need to know before trying it

0
83

Clawdbot AI security risks you need to know before trying it

Clawdbot is an AI assistant that's actually helpful, but its benefits are also its risks.

 By 

Timothy Beck Werth

 on 

Share on Facebook Share on Twitter Share on Flipboard

Two digitally animated hands.

Credit: Shutterstock / nuclear_lily

Updated on Tuesday, Jan. 27 at 5:11 p.m. ET — Clawdbot has officially changed its name to Moltbot, for very predictable reasons.


Yesterday, we wrote about Clawdbot, a new AI personal assistant that's achieved viral status in Silicon Valley. Many AI agents have been criticized for over-promising and under-delivering, but early users are raving about Clawdbot. That would be impressive enough, but this open-source tool is also completely free — no purchase price, no subscriptions, no nothing.

So, what's the catch?

Clawdbot's creator Peter Steinberger is transparent about the fact that running Clawdbot comes with certain security risks. As he writes on GitHub, "Running an AI agent with shell access on your machine is… spicy."

Before you install Clawdbot and start running it on your device (or before you buy a whole new Mac Mini to power it), you should understand the security risks.

What is Clawdbot?

First, let's quickly explain what this tool is. Clawdbot is an AI agent that runs on your device. You can give it access to AI models like Claude or ChatGPT, as well as your email, Slack, browser, and calendar. Clawdbot also has an extensive memory, and it remembers your past conversations and preferences. Because it has wide-ranging access to your computer and apps, it's able to take proactive action and execute tasks.

Mashable Light Speed

As an open-source tool, you can download it and customize it for free.

Clawdbot AI: How secure is your data?

clawdbot header

Credit: Clawdbot

With Clawdbot, your system is as secure as your security practices. That might seem obvious, but stick with us.

Clawdbot isn't a normal piece of software, which is also why installing and running it isn't as easy as downloading Zoom or Microsoft Word onto your Mac or Windows PC. Beginners can find step-by-step instructions, but you'll need some technical competence to use it properly and keep it secure. That's because Clawdbot has the ability to read and write files, run commands, and execute scripts on your device. It can also control web browsers, giving it the ability to make purchases, reserve hotels, or check into flights.

In short, everything that makes Clawdbot unique and helpful also makes it potentially risky. Generally, AI processes that happen on your device are much more secure than cloud-based AI processes. In this regard, Clawdbot is a step up from many AI tools. However, its system-level access also leaves you vulnerable.

As Steinberger writes, "There is no 'perfectly secure' setup."

Prompt injection is one of the major risks, but there are others outlined in the Clawdbot security page on GitHub. Before using Clawdbot, be aware of risks such as:

  • Bad actors could use prompt injection to get Clawdbot to misbehave

  • Bad actors could use social engineering to get access to your private data and learn information about your device

  • It could make purchases you didn't intend

  • It could damage your device by rewriting important files

How to keep Clawdbot secure:

Luckily, you can find an entire guide to securely using Clawdbot, available for free on GitHub. There's even a security audit you can periodically run to make sure your setup is as secure as possible.

However, another word of warning: If terms such as config file, remote admin API, sandboxing, localhost, reverse proxy, and legacy models don't mean anything to you, then Clawdbot may not be the right AI assistant for you.

headshot of timothy beck werth, a handsome journalist with great hair

Timothy Beck Werth is the Tech Editor at Mashable, where he leads coverage and assignments for the Tech and Shopping verticals. Tim has over 15 years of experience as a journalist and editor, and he has particular experience covering and testing consumer technology, smart home gadgets, and men’s grooming and style products. Previously, he was the Managing Editor and then Site Director of SPY.com, a men's product review and lifestyle website. As a writer for GQ, he covered everything from bull-riding competitions to the best Legos for adults, and he’s also contributed to publications such as The Daily Beast, Gear Patrol, and The Awl.

Tim studied print journalism at the University of Southern California. He currently splits his time between Brooklyn, NY and Charleston, SC. He's currently working on his second novel, a science-fiction book.

Mashable Potato

These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.

Pesquisar
Categorias
Leia Mais
Food
The Type Of Seafood You Should Never Put Down Your Sink
The Type Of Seafood You Should Never Put Down Your Sink...
Por Test Blogger1 2026-02-02 16:00:04 0 26
Music
Dave Mustaine Names Favorite (and Second Favorite) Megadeth Era
Dave Mustaine Names His Favorite (and Second Favorite) Era in MegadethIt's been a legendary...
Por Test Blogger4 2026-01-28 07:00:17 0 68
Religion
The Promise That Keeps Me Following Jesus Every Day
The Promise That Keeps Me Following Jesus Every DayWelcome to Christianity.com. My name is Aubrey...
Por Test Blogger5 2026-01-24 15:00:39 0 183
Religion
What Is Evangelism and Why Is it So Important?
What Is Evangelism and Why Is it So Important? Evangelism, simply put, is telling the...
Por Test Blogger5 2026-01-23 20:02:10 0 141
Jogos
2XKO Season 1 sees the League of Legends brawler truly come to life, with a new champion and a highly anticipated feature
2XKO Season 1 sees the League of Legends brawler truly come to life, with a new champion and a...
Por Test Blogger6 2026-01-23 23:00:36 0 163