A non-deterministic system that is susceptible to prompt injection tied to sensitive data is a ticking time bomb, I am very confused why everyone is just blindly signing up for this

OpenClaw's userbase is very broad. A lot of people set it up so only they can interact with it via a messenger and they don't give it access to things with their private credentials.

There are a lot of people going full YOLO and giving it access to everything, though. That's not a good idea.

What use is an agent that doesn’t have access to any sensitive information (e.g. source code)? Aside from circus tricks.

News aggregation, research, context aware reminders. Not nearly as useful as letting it go open-season on your data, but still enough that it would’ve been mind blowing 10 years ago.

But where does it store that information? I suppose you sandbox the agent on an operating system that gives it very few privileges?

Data scraping is an interesting use-case.