评估6个智能代理框架安全风险,发现系统级漏洞远超模型本身。
A Systematic Security Evaluation of OpenClaw and Its Variants
- 构建205个测试用例,覆盖代理全生命周期攻击行为。
- 所有代理均存在严重漏洞,早期弱点可演变为系统故障。
- 适合关注AI代理安全与系统防护的研究者和开发者。
工具增强的AI代理显著扩展了大语言模型的实际能力,但也引入了仅通过模型自身评估无法发现的安全风险。本文对六个代表性OpenClaw系列代理框架(OpenClaw、AutoClaw、QClaw、KimiClaw、MaxClaw、ArkClaw)在多种基础模型下的安全性进行了系统性评估。为支持研究,我们构建了一个包含205个测试用例的基准,覆盖代理执行生命周期中的典型攻击行为,实现框架与模型层面的风险统一评估。结果表明,所有被测代理均存在显著安全漏洞,且代理系统比孤立使用的底层模型风险更高。其中,侦察与探测行为是最常见的薄弱环节,不同框架表现出不同的高危特征,包括凭据泄露、横向移动、权限提升和资源开发。研究还发现,一旦代理获得执行能力和持久运行上下文,早期阶段的缺陷可能被放大为实际的系统级失败。整体表明,智能代理系统的安全不仅依赖于基础模型的安全性,更受模型能力、工具调用、多步规划与运行时编排之间耦合关系的影响。因此,亟需从提示层防护转向全生命周期的安全治理。
原文摘要 · Abstract (English)
Tool-augmented AI agents substantially extend the practical capabilities of large language models, but they also introduce security risks that cannot be identified through model-only evaluation. In this paper, we present a systematic security assessment of six representative OpenClaw-series agent frameworks, namely OpenClaw, AutoClaw, QClaw, KimiClaw, MaxClaw, and ArkClaw, under multiple backbone models. To support this study, we construct a benchmark of 205 test cases covering representative attack behaviors across the full agent execution lifecycle, enabling unified evaluation of risk exposure at both the framework and model levels. Our results show that all evaluated agents exhibit substantial security vulnerabilities, and that agentized systems are significantly riskier than their underlying models used in isolation. In particular, reconnaissance and discovery behaviors emerge as the most common weaknesses, while different frameworks expose distinct high-risk profiles, including credential leakage, lateral movement, privilege escalation, and resource development. These findings indicate that the security of modern agent systems is shaped not only by the safety properties of the backbone model, but also by the coupling among model capability, tool use, multi-step planning, and runtime orchestration. We further show that once an agent is granted execution capability and persistent runtime context, weaknesses arising in early stages can be amplified into concrete system-level failures. Overall, our study highlights the need to move beyond prompt-level safeguards toward lifecycle-wide security governance for intelligent agent frameworks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。