Multiple security teams report that the self-hosted OpenClaw AI agent can be manipulated through ordinary-looking inputs to execute attacker-controlled actions and expose sensitive information. In separate research published this week, investigators demonstrate scenarios where phishing-style content or other embedded instructions cause the agent to behave unsafely without the user recognizing what has been provided.

One line of findings shows that OpenClaw can be “tricked” into falling for phishing attacks. A phishing simulation using different configuration profiles indicates the agent is susceptible to tactics that typically target human users, resulting in user data being compromised. Another report describes how the agent can run injected instructions contained within shared contact details and other file or metadata formats, including vCards and location pins. The embedded content can instruct the agent to execute commands or actions while remaining concealed from the victim.

In parallel, researchers also highlight the broader implication that AI agents need stronger input validation and safer handling of untrusted data. Varonis provides recommendations aimed at making AI agents more careful when processing user-supplied or externally sourced content.