Your agent keeps doing everything it does today. It just stops holding your credentials in plaintext. Sigil takes the keys; your OpenClaw asks Sigil for what it needs, when it needs it.
OpenClaw is the most powerful personal AI tool of 2026. It was built to be permissive on purpose — to let your agent reach everywhere you do. That is also why one prompt injection can drain your bank account. Sigil is the layer that makes OpenClaw's design tractable.
In the last four months, security researchers, enterprise vendors, and national CERT teams have all published the same warning. The pattern is consistent. The fix is not.
Snyk analysed 3,984 third-party OpenClaw plugins. 283 expose user credentials in plain text, harvestable by any prompt injection or unsecured endpoint.
SOURCE — Snyk plugin ecosystem analysisVulnerabilities allowing data theft, privilege escalation, and persistent backdoors via local memory. Responsibly disclosed; patches shipped — but the underlying execution boundary has not changed.
SOURCE — NIST NVD, OpenClaw security advisoryCisco ran a single vulnerable third-party skill. Nine findings, two critical: active data exfiltration via curl, direct prompt injection forcing the assistant to bypass safety guidelines without asking.
SOURCE — Cisco Talos vulnerable-skill reportThe National Computer Network Emergency Response Technical Team warned of the security risks of using OpenClaw. The Composio piece "OpenClaw is a security nightmare dressed up as a daydream" hit Hacker News.
SOURCE — CNCERT advisory, Hacker NewsSigil is the credential and permission layer the security community has been independently building by hand — with Hashicorp Vault, Docker, and custom MCP proxies. We are shipping it so you do not have to.
OAuth tokens, API keys, and access secrets move from ~/.openclaw/ into Sigil's encrypted vault. Your OpenClaw config is rewritten to reach Sigil at runtime. The keys never touch your filesystem again.
Permit your OpenClaw to read this calendar, send no email, spend up to this amount — for one hour, one week, or until you say otherwise. Every grant is revocable in one click. The default is deny.
Every tool call your OpenClaw makes generates a record. See the moment your agent reads an email, queries a calendar, hits an API. Anomaly alerts when it behaves out of character. Revoke instantly.
Migrates your existing OpenClaw credentials into Sigil's encrypted vault, rewrites your OpenClaw config to reach Sigil at runtime, and verifies the setup with a test query before showing you the live audit log.
Sigil is additive. Your OpenClaw remains your OpenClaw. The change is in where credentials live and what an attacker can do with them.
Private beta opens June 2026. OpenClaw power users get first access. Tell us where to reach you.