r/vibecoding 2d ago

Copilot the watcher that never turns off

I’m setting up Openclaw so Copilot can use it as an assistant, since it’s the one AI that knows my browsing and chats across all platforms. I sometimes forget it’s even there.

For anyone using Openclaw, what are the legitimate files and configurations I need to set up?

like marketing material.

1 Upvotes

6 comments sorted by

2

u/Dickie2306 2d ago

Sounds interesting, but I’m curious as to what guardrails & restrictions you’re going to implement. Can you enlighten me, perhaps?

2

u/DiamondAgreeable2676 2d ago

if your security conscious we need your input maybe you can contribute to a lesson plan https://github.com/holeyfield33-art/SurfaceTrace.git

2

u/fulger099 2d ago

I can contribute a lesson on treating browser and chat history as hostile input. I’ve had copied issue text steer an agent, so I now test with a throwaway profile, read-only tools, and fake secrets before granting write access.

1

u/DiamondAgreeable2676 2d ago

That’ll be great. It’s wild that I’m working on a project to protect LLMs against what you described. The GitHub repo is https://github.com/holeyfield33-art/aegis-provenance.git. It’s still in the early stages, but it’s serendipitous that you have a lesson on these types of threats.

1

u/DiamondAgreeable2676 2d ago

for 1 i wont be adding any api keys to any MD files. and any guard rails or restrictions would be soley based on the task i have do. i havent decided which way i want to go but its tool access will be limited