# Securing OpenClaw on Mac: Monitor Its Network Connections > OpenClaw runs shell commands, files and a browser on your Mac and talks to messaging apps. Learn what its docs say about access, and how FireAI watches where it connects. FireAI Security & Research Team (HisnLabs) · Published 2026-10-04 Canonical: https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai OpenClaw is an open-source AI assistant that runs on your own devices and answers you through messaging apps. Because it can run shell commands, browse the web and read files, people searching for "openclaw security" or "is OpenClaw safe" are really asking what it can reach and where its traffic goes. This article summarises what the project documents, what published reporting found, and how FireAI, a network firewall for macOS developed by HisnLabs, can watch its connections. ## What OpenClaw is and how it runs on a Mac According to its [repository](https://github.com/openclaw/openclaw), OpenClaw is stewarded by the OpenClaw Foundation, a nonprofit, with no paid tier or hosted service. On macOS it installs with a shell installer (`curl -fsSL https://openclaw.ai/install.sh | bash`) or as an npm package (`npm install -g openclaw@latest`, which needs a recent Node.js), and `openclaw onboard --install-daemon` starts setup. The assistant connects to more than 20 messaging services, including WhatsApp, Telegram, Slack, Discord, Signal and iMessage. In practice that means a long-running Node.js process on your Mac, with a local gateway in front of it. ## What it can access The README says its tools can run shell commands, browse the web and use the file system on the host by default, and that tools execute on the host unless sandboxing is configured. Its own security documentation describes one trusted boundary per gateway: a single operator, or a team whose members trust each other. It states that OpenClaw is not designed as a hostile multi-tenant boundary. ## The documented permission model - The gateway binds to loopback on regular host installations, according to the [gateway security page](https://docs.openclaw.ai/gateway/security). - Unknown direct-message senders receive a pairing code instead of being processed, and group access is allowlisted. - `openclaw security audit` reports whether a configuration has drifted from the secure defaults, and `openclaw policy` lets you test tool access policies. - The documentation also includes an exposure checklist to follow before the gateway is made reachable beyond loopback. On network behaviour, the README says that by default OpenClaw only phones home for daily version checks, that anonymous telemetry is opt-in, and that update checks can be disabled. Beyond that, the destinations it contacts depend on which model provider and which messaging channels you configure, so no fixed list applies. ## What published reporting found Security reporting in 2026 describes exposed installations and a browser-to-local-agent flaw. Censys counted 21,639 publicly exposed instances as of 31 January 2026 [(Censys)](https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant/). Oasis Security reported ClawJacked, in which a malicious website could reach the local gateway and register a hostile device; it was fixed in version 2026.2.25 [(The Hacker News)](https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html). Kaspersky reported that content embedded in emails, documents and web pages can make OpenClaw perform unintended actions [(Kaspersky)](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/). The Register, quoting the OpenClaw 2.0 release notes, said a sandbox for contributor-controlled code is "turned off by default" [(The Register)](https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492). A fuller list with sources is in our [incident summary](https://hisnlabs.com/en/blog/openclaw-hermes-agent-security-incidents-2026). > OpenClaw acts through ordinary network connections. FireAI shows which new destination it reaches and lets you block it. Try it free. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Watching OpenClaw with FireAI FireAI is an on-device firewall for macOS developed by HisnLabs. Its [Agent profile](https://hisnlabs.com/en/docs/agent-profile) feature lists OpenClaw among the 19 AI agents it recognises, and it identifies OpenClaw by the app it runs from, or by the script its runtime runs when it is started through node, bun, deno or python. The agent’s child processes, such as a shell, git or curl it launches, are attributed to it by walking up the parent processes. FireAI then learns, for the first 3 days, which destinations OpenClaw normally contacts, grouped by domain, and flags nothing during that period. After that, a first-ever destination is flagged in Suggestions, in the AI agents card and in [Quick Review](https://hisnlabs.com/en/docs/quick-review-suggestions). An upload spike is flagged too: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB. FireAI uses metadata only, host names and byte counts, and never reads the payload of a connection. By default it flags and leaves the decision to you. In the Agent profile security mode it goes further: once learning has finished, a connection to a destination outside the baseline is blocked until you press Allow, and Keep blocked turns that block into a rule that holds in every mode. ### Setup, step by step 1. Install FireAI and finish its first-run setup, following [Install and finish setup](https://hisnlabs.com/en/docs/install-and-finish-setup). 2. Use OpenClaw as you normally do for 3 days. FireAI learns its destinations in the background and flags nothing yet. 3. Open Suggestions and find the AI agents card. When a flag appears, read the plain-words sentence, then swipe left in Quick Review to block or right for "It’s fine". 4. If you want the agent kept to places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. 5. When something is blocked, open the AI agents card and choose Allow to add it to the baseline, or Keep blocked to create a block rule. ## Limits - FireAI does not prevent prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac. - FireAI cannot see OpenClaw’s prompts, the contents of MCP tools, skills, or which files it reads, because TLS hides the payload and FireAI is not inside the agent. - OpenClaw is matched by app or script name, so FireAI labels it rather than verifying it: only Claude Code, Claude and Cursor are checked against their developer’s signature. - FireAI cannot see which messaging channels OpenClaw is connected to or what the assistant is asked to do, only the hosts it reaches and the bytes it sends. - FireAI does not scan skills, close an exposed gateway port or replace OpenClaw’s own sandbox and pairing controls. - During the 3-day learning period nothing is flagged, and upload spikes are flagged, not blocked. - A new server under a domain the agent already uses is treated as known, because destinations are grouped by domain. The full feature description is in the [Agent profile documentation](https://hisnlabs.com/en/docs/agent-profile). For the other agents FireAI recognises, see [Hermes Agent](https://hisnlabs.com/en/blog/monitor-hermes-agent-network-mac-fireai) and [any agent run by Python or Node](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai). Other agents FireAI recognises have their own guides: [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai), [Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai), [Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai), [ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai), [OpenAI Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai), [Hermes Agent](https://hisnlabs.com/en/blog/monitor-hermes-agent-network-mac-fireai), [Gemini CLI](https://hisnlabs.com/en/blog/monitor-gemini-cli-network-mac-fireai), [GitHub Copilot CLI](https://hisnlabs.com/en/blog/monitor-github-copilot-cli-network-mac-fireai), [Amp](https://hisnlabs.com/en/blog/monitor-amp-agent-network-mac-fireai), [Qwen Code](https://hisnlabs.com/en/blog/monitor-qwen-code-network-mac-fireai), [opencode](https://hisnlabs.com/en/blog/monitor-opencode-network-mac-fireai), [Aider](https://hisnlabs.com/en/blog/monitor-aider-network-mac-fireai), [Goose](https://hisnlabs.com/en/blog/monitor-goose-agent-network-mac-fireai), [Crush](https://hisnlabs.com/en/blog/monitor-crush-agent-network-mac-fireai), [Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai), [Kiro](https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai), [Trae](https://hisnlabs.com/en/blog/monitor-trae-network-mac-fireai), [Muse from Meta](https://hisnlabs.com/en/blog/monitor-muse-meta-network-mac-fireai), [any AI agent run by Python or Node](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai). ## How FireAI and HisnLabs fit in OpenClaw runs with your account’s permissions. FireAI shows, and can block, where it connects next. FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac. You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download). ## Sources - [OpenClaw repository (README)](https://github.com/openclaw/openclaw) - [OpenClaw documentation: Gateway security](https://docs.openclaw.ai/gateway/security) - [The Register, 31 August 2026: OpenClaw 2.0 pours glitter on slow-burning security dumpster fire](https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492) - [The Hacker News, 28 February 2026: ClawJacked flaw lets malicious sites hijack local OpenClaw AI agents](https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html) - [Kaspersky: New OpenClaw AI agent found unsafe for use](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/) - [Censys: OpenClaw in the Wild](https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant/) - [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile)