I ran Nvidia's NemoClaw to see if OpenClaw is finally safe, but it still has the same problems
…If you install a skill that exfiltrates your session tokens through an approved API endpoint, the sandbox will allow it without even questioning it. OpenClaw's problem is architectural, not operational No…