Research into Nvidia’s NemoClaw reveals that sandboxes don't stop AI agents like OpenClaw from leaking data. We need to rethink security from first principles.
The "sandbox doesn't stop leakage" point lands hardest if you've cleaned up after one of these locally. AutoClaw (Zhipu's OpenClaw client) leaves residue across 6+ surfaces on a Mac even after the app bundle is removed. The trust boundary an agent crosses to do useful work is the same boundary it uses to exfiltrate.
“Lasso demonstrated two distinct attack vectors against the NemoClaw environment that exploit how agents autonomously handle external data and dependencies.”
Lasso legit puts out great content. the amount of articles i’ve written that reference them at one time or another is a ton hah. great read!
The "sandbox doesn't stop leakage" point lands hardest if you've cleaned up after one of these locally. AutoClaw (Zhipu's OpenClaw client) leaves residue across 6+ surfaces on a Mac even after the app bundle is removed. The trust boundary an agent crosses to do useful work is the same boundary it uses to exfiltrate.
“Lasso demonstrated two distinct attack vectors against the NemoClaw environment that exploit how agents autonomously handle external data and dependencies.”
Lasso legit puts out great content. the amount of articles i’ve written that reference them at one time or another is a ton hah. great read!