From the source
OpenClaw can read files, run commands, install plugins, talk to the network, and act on a real machine for a real user.
Power like that is easy to describe as dangerous.
The concern is fair.
Powerful does not have to mean blind, unbounded, or impossible to audit.
Some of this has landed.
Some is rolling out.
Some is still in flight.
Some is research.
I want to be clear about the difference, because posts that blur those lines mislead readers.
Filesystem boundaries and fs-safe OpenClaw runs on your machine.
That means it can touch your documents, your codebases, and your photos.
The filesystem risk people usually reach for first is path traversal.
That risk is real, but it is also only one symptom of a bigger class of bugs: unclear boundaries.
Code thinks it is writing inside one root, then a symlink, absolute path, archive extraction, or sloppy join makes it cross another. fs-safe is one answer to that.
…





