ByteDance’s security team has issued internal security guidelines for OpenClaw and launched an enterprise service called ByteClaw for employees, according to Sina Tech. Built on Volcano Engine’s ArkClaw enterprise version, ByteClaw supports unified authentication, access control, and permission management.
The guidelines flagged five key risks tied to OpenClaw-style tools, including prompt injection, sensitive data theft, supply chain vulnerabilities, misconfigured access control, and malicious plugins. Employees are told to prioritize compliant tools such as ByteClaw and avoid deploying such tools in core production environments. [Sina Tech, in Chinese]
Related
