20.04.2026

OpenClaw: The new AI superstar

AI Snack with Inga
OpenClaw: Productivity booster or a hacker’s paradise?

It’s rare for the tech world to collectively hold its breath, but at the moment, GitHub stars are skyrocketing for a project called OpenClaw (still known to many as Moltbot). And that is indeed remarkable. 2 million visitors in a week, nearly 200,000 GitHub stars – this is no longer just ordinary hype.

What exactly is behind it all? We’ve taken a thorough look behind the scenes.

OpenClaw is an open-source agent system. Or to put it another way: an AI that doesn’t just respond – it takes action.

“The AI that actually does things” (OPENCLAW) sums it up quite well.

The system runs locally on your computer and independently carries out tasks that you control, for example, via a WhatsApp chat. It’s essentially a digital assistant with access to tools, browsers, files – and, depending on the configuration, even your entire system. Imagine chatting with your agent on the train on your way to work, whilst it plans your daily routine and takes care of those annoying tasks straight away.

Further examples:

  • Publishing blog posts directly in WordPress
  • Boosting rankings as a smart AI SEO agent
  • Communicate via messaging apps such as Telegram
  • Create AI avatar videos and animations
  • Clone your voice for voice memos
  • Book flights
  • Organise appointments, take minutes, and much more

In other words, an operational AI agent that actively integrates into your workflows. 

For content creators, this means:

Research → Blog → Publication → Social media posts – all automated.

 

For businesses, for example:

Marketing, SEO, communications, appointment scheduling, internal processes – all automated.

 
This can be a real productivity booster.

Now for the less glamorous bit.

If configured incorrectly, OpenClaw can:

  • execute shell commands
  • read and write files
  • Run scripts
  • Use API keys
  • React automatically to web content

This means:
If you’re not careful or install a tampered ‘skill’, things can very quickly become problematic.


Security analyses refer to:

  • API keys in plain text on the file system
  • Publicly accessible instances without a password
  • Exposed logs containing sensitive data
  • Prompt injection attacks
  • Manipulated community repositories

In some cases, dozens of security issues were found in skills. There were documented remote code execution vulnerabilities, compromised packages and actual data leaks in unprotected installations.

Some experts describe poorly secured instances as a “hacker’s paradise”.

The risks associated with this autonomy are high. And it can cause more problems than the time saved in the end.

Just between us: I wouldn’t even let OpenClaw near my main computer at the moment. If you’re particularly keen to take risks and want to watch as your account gets emptied or sensitive passwords end up in plain text on the internet – go ahead! Personally, I place the utmost importance on data security. The risk of prompt injection (i.e. malicious hidden commands) is an unresolved problem. All it takes is a tampered email that the agent reads, and it’ll blurt out your API keys.

If we’re going to test it, then:

  • On isolated hardware
  • No access to sensitive data
  • No open ports
  • Strict tool whitelists
  • Manual approval of critical actions

And only with non-critical workflows.

What concerns me almost even more than the issue of security is the question of control. Would I, for example, allow a blog post to be published entirely autonomously?

No.

I’m convinced that the best quality is achieved when humans and AI work together.

Agents are great for:

  • Time-consuming
  • Structural work
  • Routine processes that can be automated

But handing over our thinking? I think that’s dangerous. Our thinking is what makes us unique and is our competitive advantage. If we delegate that, we’ll lose more in the long run than we’ll gain.

It is obvious that such systems will change the nature of jobs. Repetitive tasks are ideally suited to autonomous agents. SEO routines, content distribution, scheduling, traditional administrative tasks – all of these can be automated.

The crucial question will be:

  • How much control do we relinquish?
  • How much knowledge do we share with these systems?

After all, ultimately, these agents will have access to our data. And data is power.

Cybersecurity and data protection will not be side issues when it comes to agent systems – they will become a central factor.

OpenClaw is technologically impressive. Community-driven. Radically open. And a clear harbinger of things to come.

Agent systems like this will probably be the norm in a few years’ time.

But as things stand today?

I still see considerable risks when it comes to widespread use – particularly outside of experienced tech environments. If you look at the security reports and analyses, it certainly makes you feel a bit uneasy.


Hence my stance:
Keep an eye on it? Absolutely.

Test them? Yes – but in a controlled manner.

Deploy them blindly in production? Not at present.


Finally, a general reflection on the topic of AI and autonomous agents.


Will such agents become part of our everyday lives?
To be honest, I believe so.

It’ll be almost impossible to avoid.

Just as we’ve got used to smartphones, cloud tools and voice assistants, autonomous AI agents will also gradually find their way into our everyday lives. First as a trial. Then as a productivity tool. And eventually as something we take for granted.

The more intriguing question isn’t whether they’ll arrive. It’s: how much control will we relinquish?

Because this is about more than just a new tool. These systems access our data – emails, documents, calendars and communication histories. They organise, prioritise and make decisions – partly autonomously.


And this raises a fundamental question: how much information are we willing to share with such an agent? How dependent do we want to become on it?
In the worst-case scenario, it’s not just an account that gets hacked – but our entire digital life. If an agent is integrated deeply enough, it knows our contacts, projects, habits and payment flows. It knows how we think and work. That’s convenience on a whole new level. But convenience always comes at a price.

We gain efficiency, speed and automation. We risk dependency, loss of control and new vulnerabilities.

At its core, this is a question of freedom. Freedom means being able to delegate tasks. But true freedom also means not relinquishing control entirely.


I firmly believe:
’ Responsibility always lies with people.

Agents can take a huge load off our shoulders. They can take on repetitive tasks, speed up processes and create space for creative work. But they should never replace our thinking or make unchecked decisions that have long-term consequences.

The key skill of the future will not be doing everything yourself. Rather, it will be knowing what to delegate – and what not to.


It remains an exciting time. Technologically, we are only just beginning. Socially, too, we probably are.
And that is precisely why we should not just ask:

‘What can the system do?’

But above all:

‘What am I prepared to entrust to it?’