OpenClaw 보안: 시작해야 할 강화된 기준선

Self-hosting OpenClaw does not mean it's self-securing. A post on r/openclaw highlights that the harder part isn't getting the bot running—it's deciding what the bot is allowed to do, who can reach it, and how much damage a bad message can cause. The post walks through OpenClaw's documented hardened baseline config, which starts closed and widens later.
Gateway: Local-Only First
The most common mistake is exposing the Gateway. The hardened baseline requires:
gateway.mode: "local"gateway.bind: "loopback"gateway.auth.mode: "token"
Expose later only when you understand the boundary you're widening.
DM Session Isolation
If multiple people can DM the bot, you need session isolation to prevent context bleed. The hardened baseline uses session.dmScope: "per-channel-peer". The rule: never combine shared DMs with broad tool access.
Tools Blast Radius
Most people think about who can message the bot before considering what authority a message inherits. The hardened baseline:
tools.profile: "messaging"- Denies
group:automation,group:runtime,group:fs - Denies
sessions_spawnandsessions_send exec.security: "deny"andexec.ask: "always"elevated.enabled: false
Start from denial, then re-enable the minimum you can justify.
Groups: Mention-Gated
Groups should be opt-in and mention-triggered unless you have a strong reason to loosen. The baseline uses requireMention: true for all groups.
Practical Starting Config
{
"gateway": {
"mode": "local",
"bind": "loopback",
"auth": {
"mode": "token",
"token": "replace-with-long-random-token"
}
},
"session": {
"dmScope": "per-channel-peer"
},
"tools": {
"profile": "messaging",
"deny": [
"group:automation",
"group:runtime",
"group:fs",
"sessions_spawn",
"sessions_send"
],
"fs": {
"workspaceOnly": true
},
"exec": {
"security": "deny",
"ask": "always"
},
"elevated": {
"enabled": false
}
},
"channels": {
"whatsapp": {
"dmPolicy": "pairing",
"groups": {
"*": {
"requireMention": true
}
}
}
}
}
Four Questions Before Widening
Before opening anything, ask:
- Can the Gateway be reached from more places than needed?
- Can one person's DM context leak into another's session?
- Can an ordinary message inherit tool authority broader than intended?
- Can a room trigger the bot too easily?
If yes, the fix is config hardening, not prompt engineering. OpenClaw gives you the surfaces—use them.
📖 Read the full source: r/openclaw
👀 See Also

클로드 코드가 23년 된 리눅스 커널 취약점 발견
Anthropic의 연구원 Nicholas Carlini가 Claude Code를 사용하여 Linux 커널에서 원격으로 악용 가능한 여러 힙 버퍼 오버플로우를 발견했으며, 그중 하나는 23년 동안 숨겨져 있었습니다. AI는 전체 커널 소스 트리를 스캔하면서 최소한의 감독으로 버그를 찾아냈습니다.

FORGE: LLM 시스템을 위한 오픈 소스 AI 보안 테스트 프레임워크
FORGE는 실행 중에 자체 도구를 구축하고, 군집으로 자가 복제하며, 프롬프트 주입, 탈옥 퍼징, RAG 누출을 포함한 OWASP LLM Top 10 취약점을 다루는 자율 AI 보안 테스트 프레임워크입니다.

블라인드폴드: 클로드 코드가 .env 파일을 읽지 못하게 하는 플러그인
Blindfold은 실제 비밀 값을 OS 키체인에 보관하고 {{STRIPE_KEY}}와 같은 자리 표시자를 사용하여 Claude Code가 .env 파일의 실제 비밀 값에 접근하지 못하도록 방지하는 새로운 플러그인으로, 직접 접근 시도를 차단하는 훅을 포함합니다.

프론티어 AI, CTF 대회의 판도를 바꾸다 — GPT-5.5, 미친 pwn 문제를 단번에 해결하다
Claude Opus 4.5와 GPT-5.5는 중간에서 어려운 수준의 CTF 챌린지를 자율적으로 해결할 수 있어, 점수판이 보안 실력 대신 오케스트레이션과 토큰 예산의 척도가 되고 있습니다.