# How FireAI Limits the Network Damage of OpenClaw’s Risky Mistakes on Your Mac > Five documented risk classes of running an AI agent with shell access on macOS, the FireAI network controls that limit each, and the risks a firewall cannot address. FireAI Security & Research Team (HisnLabs) · Published 2026-09-30 Canonical: https://hisnlabs.com/en/blog/fireai-protects-desktop-from-openclaw-mistakes Running an autonomous agent such as OpenClaw on a Mac gives a language model the permissions of the account that starts it, and published security reporting since January 2026 documents several ways that arrangement has gone wrong. Most of those failures end with a network connection: data sent to an unknown server, a local service reachable from outside, or a downloaded payload. FireAI is a network firewall for macOS, so it can limit that part. It cannot stop an agent from reading or deleting local files, and this article says where the boundary lies. ## Background OpenClaw’s own documentation states that tools run on the host unless sandboxing is configured, that inbound messages are untrusted input, and that agents with message-tool access can send across conversations and channel providers by default [[1]](https://docs.openclaw.ai/gateway/security). An agent therefore combines three things: it reads untrusted text, it can act on the machine, and it can communicate outward. A firewall addresses the third. The sections below take each documented risk class in turn, name the FireAI control that applies and list the steps to set it up. The general comparison of OpenClaw with Hermes Agent is in a [separate article](https://hisnlabs.com/en/blog/openclaw-vs-hermes-agent). > **Note:** Every FireAI control below is described in the FireAI documentation. Menu names may change between versions; the linked pages are kept current. ## Before the steps: how FireAI identifies an agent FireAI identifies an app by the code signature of the executable that opens the connection or, for an unsigned program, by its path. It has no integration with OpenClaw or Hermes Agent and does not recognise either by name. Agents of this kind run inside a general-purpose interpreter, typically Node.js or Python, so FireAI shows connections from “node” or “python3”. A rule on that interpreter applies to every script the same binary runs, including unrelated tools. Per-script attribution is not available today. Every rule below therefore applies to the interpreter as a whole, and a rule that blocks the agent’s destinations also affects any other script the same interpreter runs. Reading the interpreter’s name in a prompt and matching it to the moment the agent was working is the practical way to attribute a connection. ## Risk 1: prompt injection that sends data out Kaspersky reported that OpenClaw proved susceptible to data extraction through malicious email content, including a researcher’s demonstration of extracting private cryptographic keys by embedding instructions in a message, and users reporting that the bot dumped home directory contents into a group chat after a social-engineering prompt [[3]](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/). The exfiltration step is an outbound connection from the agent’s process to a server the attacker controls or to a messaging service. FireAI identifies each app by its code signature and checks its rules for every connection. In Alert mode it pauses the first connection to a destination that has no rule and asks [[12]](https://hisnlabs.com/en/docs/answer-your-first-connection-prompt). The setup that limits this risk is an allow-list built around the agent: 1. Start the agent once and let FireAI show its first connections. In the prompt, click Options, choose Always and The whole website for the model provider’s domain you actually use, then Allow. The prompt names the interpreter, not the agent. 2. Block every other destination for that app: open Rules, click Add rule, choose Stop the connection, pick the interpreter the agent runs under (node or python3), and set Which website or server to Anywhere on the internet. 3. Open the Allow rule you made for the model provider and turn on Quick, so that the first matching [Quick rule](https://hisnlabs.com/en/docs/quick-rules) decides before the broad Block is considered. 4. Answer later prompts with Block unless you can name the destination. A prompt for an unfamiliar domain right after the agent reads an email is the signal the control is designed to surface. 5. Open Details in the prompt to check the address, port and code-signing status, and use Why block this? when it is offered. Limits apply. If the agent is allowed to reach a messaging service or its model provider, an injected instruction can send data there, and FireAI sees how much is sent, not what it says, because it does not read the contents of encrypted connections ([how connections are inspected without decryption](https://hisnlabs.com/en/docs/protocol-inspection-without-decryption)). ## Risk 2: malicious or compromised skills Koi Security audited 2,857 skills on ClawHub and identified 341 malicious ones, 335 of them from a single campaign; eSecurity Planet reports the skills asked users to install “prerequisites” that delivered the Atomic macOS Stealer, which targets browser credentials, keychain passwords, wallets, SSH keys and API tokens [[6]](https://www.esecurityplanet.com/threats/hundreds-of-malicious-skills-found-in-openclaws-clawhub/). A skill runs with the agent’s permissions, so its network calls appear as the agent’s. FireAI’s controls act on where those calls go, in two ways. First, the allow-list from the previous section refuses destinations that were never approved. Second, FireAI can use public threat lists: 1. Open the threat lists page in FireAI and turn on Use public threat data. FireAI then downloads lists such as abuse.ch URLhaus, ThreatFox and Feodo Tracker once a day, and your traffic is never sent to them. See [the documentation](https://hisnlabs.com/en/docs/threat-intelligence-feeds). 2. Turn on Block what a threat list confirms, so a confirmed match becomes a block rather than only a flag. 3. Open Threats and use Investigate on any row you do not recognise; the dossier explains the connection step by step. 4. Keep Connection history on (Settings, Connection history) to review later which app contacted which destination; it stores a 7-day record on this Mac only. A skill that contacts a server no list knows, or that only reads local files, is not caught by this control. Reviewing the skill before installation remains the primary defence. ## Risk 3: a local gateway reachable from outside or from a browser Censys recorded growth from roughly 1,000 to 21,639 publicly exposed OpenClaw instances in under a week to 31 January 2026, while noting the Gateway is designed to listen locally on TCP port 18789 [[4]](https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant/). Kaspersky described installations without authentication that trusted localhost and sat behind misconfigured reverse proxies [[3]](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/). Oasis Security’s ClawJacked finding showed that a web page could connect to the local Gateway from the browser; it was fixed in OpenClaw 2026.2.25 [[5]](https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html). FireAI enforces rules on incoming connections to the Mac as well as outgoing ones, though it never prompts about incoming connections. See [the documentation](https://hisnlabs.com/en/docs/how-the-network-filter-works). The relevant steps: 1. Switch to Coffee shop mode when the Mac is on a network you do not control. It blocks incoming connections and file and screen sharing to other devices, as described in [security modes](https://hisnlabs.com/en/docs/security-modes). 2. To make this automatic, attach Coffee shop mode to your public places as documented in [places](https://hisnlabs.com/en/docs/rule-profiles-by-wifi), or use [Coffee Shop Armor](https://hisnlabs.com/en/docs/coffee-shop-armor), which the FireAI documentation describes for public Wi-Fi. 3. In Rules, add an incoming Block rule for the agent app (under Advanced, set Direction to incoming) on any network you do not fully trust. 4. Check the agent’s own configuration too: the Gateway should stay bound to loopback, as OpenClaw’s documentation describes for regular host installs [[1]](https://docs.openclaw.ai/gateway/security). > **Warning:** The FireAI documentation does not state that traffic between a browser and a service on the same Mac (loopback) is filtered. Treat ClawJacked-type attacks as a matter for updating the agent, not for the firewall. ## Risk 4: credentials and files leaving the machine The same reporting lists API keys, tokens, SSH keys and wallet files as targets [[6]](https://www.esecurityplanet.com/threats/hundreds-of-malicious-skills-found-in-openclaws-clawhub/). For network exfiltration, three FireAI features apply: 1. Protocol inspection blocks unencrypted web requests that carry card numbers, bank details, passwords or keys before they leave the Mac, and blocks data smuggled out as DNS lookups; nothing is stored or sent. See [the documentation](https://hisnlabs.com/en/docs/protocol-inspection-without-decryption). 2. The World map and Activity show each connection live and in a searchable history. Right-click a connection for Deny host, Block IP for all apps, or Block this app everywhere. See [the documentation](https://hisnlabs.com/en/docs/activity-and-connection-history). 3. Ask FireAI accepts plain-language orders such as “block” followed by an app’s name, as it appears in FireAI (the interpreter, for an agent), shows a preview and applies nothing until you click Apply. See [the documentation](https://hisnlabs.com/en/docs/block-an-app-or-a-company). A credential sent to an allowed destination over an encrypted connection is outside what FireAI can see. ## Risk 5: unexpected connections while nobody is watching Agents work unattended. OpenClaw’s documentation notes that unknown senders are paired by default and that agents may message across channels unless restricted [[1]](https://docs.openclaw.ai/gateway/security); Hermes Agent’s documentation describes a command approval system whose mode can be set to off [[7]](https://hermes-agent.nousresearch.com/docs/user-guide/security). Unattended runs are where a mistaken or injected action does the most before a person notices. 1. Use a timed rule, created through Ask FireAI, so the agent only connects during set hours, for example “allow the agent during work hours”; the four built-in windows are night, evening, work hours and weekends. See [the documentation](https://hisnlabs.com/en/docs/timed-rules). 2. Use Paranoid mode when the agent runs unsupervised. It blocks tracking traffic, unsigned apps and every unencrypted port, and even Apple’s system tools must be approved [[10]](https://hisnlabs.com/en/docs/security-modes). 3. Use Under attack mode or the kill switch when an agent misbehaves. Under attack allows only apps with an explicit Allow rule and stops asking. The kill switch refuses new connections to anything outside the home or office network, and is also reachable from the menu bar [[11]](https://hisnlabs.com/en/docs/kill-switch). 4. Leave FireAI Pilot for other apps, or review it in Suggestions, as it answers confident connections automatically; for an agent, explicit rules are easier to audit. > FireAI checks every connection an app makes and can cut new connections in one click. A 17-day trial is available from HisnLabs. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Recommendations 1. Run the agent in a dedicated macOS user account or a virtual machine, with only the folders it needs. 2. Give it revocable, narrowly scoped credentials and never your main password manager or SSH keys. 3. Read a skill’s source before installing it, and refuse any that ask you to paste a shell command as a prerequisite. 4. Keep the agent updated; the ClawJacked fix reached users only by updating. 5. Keep command approval on manual where the agent offers it. 6. Combine the allow-list, the kill switch and a mode that fits the place you work. ## Limitations - FireAI sees the interpreter that opens a connection (for example node or python3), not the agent’s name; a rule applies to everything that interpreter runs. It has no integration with these agents. - FireAI controls which app connects where and can cut the internet. It cannot prevent an agent from deleting, encrypting or reading local files, running commands, or changing settings on the Mac. - The kill switch refuses new connections; it does not tear down ones already open. - FireAI does not read the contents of encrypted connections, so data sent to an allowed destination is not inspected. - Filtering of loopback traffic between a browser and a local service is not documented; update the agent to close such flaws. - Threat lists only block what they confirm; a new server or a skill with local-only behaviour is not covered. - A firewall does not fix an agent’s own design choices, such as a Gateway bound to a public address. - Complementary measures are required: least-privilege accounts, sandboxes or virtual machines, backups, and reviewing skills before installation. ## How FireAI and HisnLabs fit in Agents act fast. A network firewall decides where they are allowed to connect. FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac. You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download). ## Sources - [OpenClaw documentation: Gateway security](https://docs.openclaw.ai/gateway/security) - [OpenClaw: project repository and README (GitHub)](https://github.com/openclaw/openclaw) - [Kaspersky: New OpenClaw AI agent found unsafe for use](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/) - [Censys: OpenClaw in the Wild, mapping the public exposure of a viral AI assistant](https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant/) - [The Hacker News: ClawJacked flaw lets malicious sites hijack local OpenClaw AI agents](https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html) - [eSecurity Planet: Hundreds of malicious skills found in OpenClaw’s ClawHub](https://www.esecurityplanet.com/threats/hundreds-of-malicious-skills-found-in-openclaws-clawhub/) - [Hermes Agent documentation: Security](https://hermes-agent.nousresearch.com/docs/user-guide/security) - [FireAI docs: Rules](https://hisnlabs.com/en/docs/per-app-rules) - [FireAI docs: Block an app or a company](https://hisnlabs.com/en/docs/block-an-app-or-a-company) - [FireAI docs: Security modes](https://hisnlabs.com/en/docs/security-modes) - [FireAI docs: Kill switch](https://hisnlabs.com/en/docs/kill-switch) - [FireAI docs: Answer your first connection prompt](https://hisnlabs.com/en/docs/answer-your-first-connection-prompt)