Cowork’s security model is architecturally stronger because it sandboxes via Apple’s Virtualization Framework and restricts scope to explicitly granted folders. But as the plugin ecosystem grows, it will face supply chain pressures too. The “lethal trifecta” applies to all agent frameworks: private data access + untrusted input exposure + external communication capability. The specific mitigations vary (OpenClaw’s Docker sandboxing vs.
No discussion yet. Be the first to share your thoughts!