Skip to content
Search
paperJune 2026Unreviewed

Security Engineering of OpenClaw: Analyzing Attack Surface Expansion and Trust-Boundary Violations

Saeid Jamshidi, Arghavan Moradi Dakhel, Kawser Wazed Nafi, Foutse Khomh

Abstract

Agentic large language model (LLM) systems can now execute actions, not only produce text. When model outputs trigger privileged operations such as shell commands, browser automation, or external tool calls, the security problem shifts from alignment alone to system configuration and structural design. We analyze OpenClaw, a self-hosted multi-agent system in which LLM outputs can execute commands and interact with tools and services. We measure compromise probability, boundary failures, privileg

Categories

Cite

@misc{jamshidi2026security,
  title = {{Security Engineering of OpenClaw: Analyzing Attack Surface Expansion and Trust-Boundary Violations}},
  author = {Saeid Jamshidi and Arghavan Moradi Dakhel and Kawser Wazed Nafi and Foutse Khomh},
  year = {2026},
  month = jun,
  eprint = {2606.15008},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.15008}
}