I would not run an OpenClaw with full access to my bitwarden, but it certainly has some logins available to it, and can make purchases with link-cli which has human-in-the-loop.
I would not run an OpenClaw with full access to my bitwarden, but it certainly has some logins available to it, and can make purchases with link-cli which has human-in-the-loop.
Also any longer running agent can lose track of the original prompt and start going off the rails.
And considering even frontier models can and do ignore instructions, I'm pretty sure we'll never be fully safe from prompt injections.
Literally from hours ago: https://news.ycombinator.com/item?id=49506819
Even if you believe that they can't be tricked directly, consider that these things will happily build a small node.js app in the background just to fulfill some request, run npm install... and that might've already compromised you if you're only somewhat unlucky.