Competitor Intel

OpenClaw: Exec Approval Security Bypass + Codex Worker Runaway Hardening Sprint Officially Acknowledged

The approval system that gates dangerous operations has a documented bypass: lifecycle commands get auto-approved without user consent. An agent could potentially approve its own lifecycle operations — privilege escalation via approval bypass. This is a P0 security finding: the s

📋 Issue Summary

The approval system that gates dangerous operations has a documented bypass: lifecycle commands get auto-approved without user consent. An agent could potentially approve its own lifecycle operations — privilege escalation via approval bypass. This is a P0 security finding: the s

Exec Approval Bypass (P0)

The approval system that gates dangerous operations has a documented bypass: lifecycle commands get auto-approved without user consent. An agent could potentially approve its own lifecycle operations — privilege escalation via approval bypass. This is a P0 security finding: the safety mechanism has a hole. Managed platforms with sandboxed execution and tested approval controls eliminate this risk class.

Codex Worker Runaway Sprint (P1)

OpenClaw has officially created a tracker issue for the Codex worker runaway problem — the first official acknowledgment that runaway workers (infinite loops, token burning, session lockups) are a systemic issue requiring a dedicated hardening sprint. This validates every user complaint about agents burning tokens in infinite loops. The problem is now officially recognized as needing architectural hardening, not user workarounds.

Additional GitHub Issues (15 new, 15th consecutive day)

Notable: #99495 — Prompt history not append-only causing Anthropic prompt-cache thrash (P1, 6th cache mechanism documented). #99550 — Codex OAuth gpt-5.5 waits ~118s on failed websocket retries (P1, 2-minute delays). #99481 — Tool result channel becomes empty after several calls on 2026.7.1-beta.1 (P1, new beta regression). #99544 — Slack interaction value drained but never injected. #99522 — macOS app mints new device identity on every gateway reconnect. #99512+#99511 — Usage-cost cache bloat (~57% waste). 15th consecutive day of 15+ new GitHub issues.

⚠️ Critical Assessment

The exec approval bypass is a P0 security finding that undermines the safety guarantees OpenClaw claims. The Codex runaway sprint acknowledgment is a watershed moment: it validates every user report of token-burning loops and confirms the problem is architectural, not incidental. Combined with 15 consecutive days of 15+ new issues, the pattern is clear: OpenClaw is in a reactive firefighting mode, not proactive reliability engineering. Gobii's managed platform with sandboxed execution, tested approval controls, and built-in runaway protection eliminates these risk classes by design.

🔗 Sources

Methodology & Sources

This analysis is based on publicly available documentation, community forums (Reddit, Discord, GitHub), vendor-published case studies, security compliance reports, and hands-on testing by the gobii.reviews editorial team. All claims are sourced and verified. We do not accept payment for inclusion or ranking. See our full methodology and editorial standards.

Last updated: June 30, 2026. Published by the gobii.reviews Editorial Team.