Forum

Sandboxing and Exec...
 
Notifications
Clear all
Sandboxing and Execution Isolation

Container and Runtime Hardening

Hardening the container or process environment OpenClaw agents run in — rootless containers, read-only filesystems, dropped capabilities, and runtime security profiles.
Topics: 28   /   Posts: 190

Sandbox Escapes and Breakout Research

Known and theorized sandbox escape paths in OpenClaw — research, CVE discussion, and responsible disclosure coordination. Claims should come with reproducible steps or clear reasoning.
Topics: 30   /   Posts: 140

Seccomp, AppArmor, and LSM Profiles

Writing and tuning Linux Security Module profiles for OpenClaw workloads — sharing working seccomp filters, AppArmor profiles, and discussion of what each syscall restriction actually buys you.
Topics: 49   /   Posts: 238

Sandboxing and Execution Isolation

How OpenClaw isolates agent-executed code and tool calls — container runtimes, syscall filtering, seccomp profiles, and escapes. For anyone who needs to understand what actually runs with what privileges.

No topics were found here