I like your analogy of OpenClaw==Linux. Paradoxically, Linux was simple and secure in its early days due to (among other reasons) being open source from (almost) the beginning. Vulnerabilities were found and fixed by the community. OpenClaw has some of this, but it's built on a foundation that was never intended for a secure trust layer (LLMs).
One-click, standard, and secure containers (especially for a non-technical audience) are a super idea.