Two separate security research efforts have demonstrated critical vulnerabilities in OpenClaw, the self-hosted AI agent, showing it can be manipulated to execute arbitrary code or exfiltrate sensitive data through seemingly innocuous inputs. Imperva found a prompt injection vector leveraging how OpenClaw processes message objects, while Varonis identified an "agent phishing" technique that exploits the agent's predisposition to be helpful even against its own security rules.