Taught by Humans - < tbh />

This is an older piece. The information may be out of date.

Should You be Using Moltbot (formerly Clawdbot) as Your AI Agent?

By Laura Gemmell | 28 January 2026 ยท Updated September 2026

AIData PrivacyOpen Source AI

Clawdbot (now Moltbot - after Anthropic, very reasonably, raised concerns about the name.) is a self-hosted AI assistant that runs on your own machine. You message it via WhatsApp, Telegram or something similar, and it replies like a chatbot.

But it isn't just sending replies or writing documents. It acts. It can open files, browse the internet, run scripts, send emails and manage your calendar. All from your phone.


What People Mean By Agentic AI

This is what people are calling agentic AI. A system that decides how to carry out a task, and then does it. Unlike ChatGPT, which sometimes does what you ask it.

There's no platform in the middle. It runs locally, uses APIs you configure, and has access to your system. That gives you control, technically. But it also gives the tool freedom to act as it decides.

If you're curious about running AI locally, my intern wrote a guide: Open-source AI on your device


Why I Haven't Used It

Not because it isn't clever. It is. But clever tech is often more worrying. For example, Claude Code and how people use it, deeply unnerves me.

My actual concern is the level of access it has is a lot. This isn't a chatbot in a browser tab. It's something that can take action on your laptop, based on a message you send.

That means you are trusting:

  • the model
  • the system setup
  • yourself to have secured it properly

And I'm not sure this is something we should be doing. Especially people who are vibe coding their way to using tools like this without understanding.


The Growing List Of Concerns

My concerns aren't even theoretical, it's already happening:

ConcernDetails
Exposed InstancesSome Clawdbot setups have been found publicly accessible online, with no authentication in place. Anyone with the link could interact with the bot and, in some cases, trigger actions on someone else's system.
Prompt Injection RisksMalicious or unexpected messages can manipulate the assistant into taking actions you didn't intend. If it's acting on natural language alone, you have to assume it can be tricked.
Full System AccessThe bot often runs with the same permissions as the user. Without isolation or sandboxing, it can move files, install packages or run scripts based purely on a chat message.
Persistent MemoryIt stores previous interactions by design, which may be useful, but also means it's holding onto more data than many users realise.

We've Seen This Before

This pattern of early adopters being stung, and forgetting about data privacy and security isn't actually new (but is being worryingly common):

  • Early ChatGPT users including teachers shared students' personal data, and we've all heard the law cases where hallucinated cases were quoted.
  • Early vibe coders exposed their API keys and entire customer databases by accident
  • Now people are giving AI access to their machines, with barely any safety layer

Have I mentioned I'm worried?


Should You Be Using It?

If you know what you're doing and you've locked it down properly, fine.

But no - the general AI user should not be running this.

We can complain about OpenAI, Anthropic, Google, etc to death but that doesn't mean random unsecure open source is the answer.