Clawdbot...

Everyone and their brother is talking about Clawdbot, but as several others have pointed out- an agent with that many connections could be a security nightmare if it can be prompt injected.

But since it supports OpenAI and Ollama endpoints... I wonder how well it would work if I stuck a Wilmer workflow to act as a middleware between it and the LLM, and had the workflow try to detect for prompt injection?

Fairly straight forward in terms of implementation, though whether the gating will work well is another matter. But even just using local models, I'd think GLM 4.7 Flash or Qwen3 30b should do alright for extracting most standard adversarial prompts. Sure, you'd take a speed hit, but you'd also reduce the risk of it emailing everything it knows about you to some rando.

Still not perfect though. Hmm...