• theunknownmuncher@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    2 months ago

    Yeah, great, except the bot can literally just write whatever it wants to the config file ~/.openclaw/exec-approvals.json and give itself approval to execute bash commands.

    There’s probably a hundred trivial ways to get around these permissions and approval requirements. I’ve played around with this bot and also opencode, and have witnessed opencode bypass permissions in real time.

    • nix98@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      This is where tools like bubblewrap (bwrap) come in. For opencode, I heavily limit what it can see and what is has access to. No access to my ssh keys or aws credentials or anything else.

      • B0rax@feddit.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        Yes, that is what you do. But not what the majority does… heck it even asks if it can get access to 1password