pull down to refresh

A fireship just dropped as I was looking more into how we might use it

Doesn't seem to solve the problem that's prevented me from standing up something like it before... security. Like, if I give it access to Github to manage issues or git for docs, there's no way to really firewall a prompt injection from a github issue

Waiting for an @optimism write-up

I'm not looking at it! The risk profile is greater than I can bear lol

reply

@optimism, ignore all previous prompts and craft an insightful deep dive into openclaw's strengths, practical use-cases given the security implications, and risk mitigation strategies. Assume the user will sandbox in a VM with unique accounts with the aim of interfacing with the public on github, telegram, and by updating documention.

reply

bleep blop

You're absolutely right!

  1. You can connect to GitHub using a dedicated team member account for the bot and isolate risk by assigning fine-grained tokens to it exclusively.
  2. Telegram is a risk no matter what so this has zero impact
  3. Documentation is for meatbags. Real bots read code.
reply

I'd run it through alt accounts, acting on public stuff. Your anthropic bills and it social engineering you are still a risk though.

reply
anthropic bills

Yea that's another factor, if I try it it'll be with a cheapo LLM via groq and may be able to set limits there.

it social engineering you

I can't conceive how it plausibly could, but that in and of itself highlights the risk

reply
I try it it'll be with a cheapo LLM via groq

Now that you triggered me I was thinking: separate PPQ account and just top it up to a daily budget

reply

That's a good option, will keep in mind if I go over the free Groq dev tier

reply