Skip to content
dots.online

Security and privacy

Give your agent a key, not the whole keyring

An agent with access to your email, cards and accounts is as powerful as you are online, and it can be fooled by a web page. These are the risks that have already happened, and the settings that stop them.

What actually goes wrong

Oversharing

An agent completes a task by sharing more than you meant, like the Muse user whose home address was given to a Marketplace buyer.

Prompt injection

A web page, email or document hides instructions, and the agent follows them as if they came from you.

Acting without approval

The agent decides a step is fine and does it: accepting an offer, sending a message, paying an invoice.

Exposed infrastructure

Self-hosted gateways left open to the internet, or outdated versions with known flaws, hand your agent to a stranger.

Runaway spending

A loop or a misunderstanding turns one purchase into many, or burns through API credits overnight.

Blocked or mistrusted agents

Sites like Amazon block agents that do not identify themselves, and your account can be flagged for using one.

Six rules that prevent most problems

  1. 01

    Start read-only

    Let the agent see before it can act. Add write access one app at a time.

  2. 02

    Approval for anything irreversible

    Sending, paying, sharing personal details, deleting and publishing always need your yes.

  3. 03

    Separate money

    Give the agent a virtual card with a low limit, never your main card or bank login.

  4. 04

    Keep secrets out of chat

    Use the agent's password vault where it exists, and never paste passwords, codes or ID numbers into the conversation.

  5. 05

    Watch the activity log

    Check what the agent did in its first week, every day. Patterns show up fast.

  6. 06

    Know the off switch

    Learn how to pause the agent and revoke app access before you need to.

Settings that matter in each agent

Dots
  • Write Custom Rules before connecting email: allow, require approval or ban specific actions.
  • Keep proactive research on; it is read-only and cannot send or change anything.
  • Do not connect your own computer unless a task needs it, and revoke access afterwards.
  • Check the Activity View, including background tasks.
  • On a personal plan, decide whether your Dot's work may be used for training in data controls.
Muse
  • Tell Muse in writing never to share your address, phone number or schedule.
  • Keep purchases and offer acceptance behind approval.
  • Do not ask it to shop on Amazon; the retailer blocks it and warns about its terms.
  • Watch for Meta's in-app safety warnings and update the app promptly.
  • Connect sensitive accounts only when a task needs them; your Muse VM keeps copies of connected data.
Gemini Spark
  • Grant access to Google apps one by one rather than all at once.
  • Supervise event-triggered tasks until you trust them.
  • Review which tasks are scheduled and delete the ones you no longer need.
  • On business accounts, ask your admin which Spark controls apply.
Claude
  • Connect only the connectors a task needs and remove them afterwards.
  • Name the sources Claude may use for research tasks.
  • Review generated documents before sharing them; they may include content from connected files.
OpenClaw
  • Update to the latest stable version; anything before 2026.4.22 has known critical flaws.
  • Keep the gateway bound to loopback and reach it through SSH or Tailscale.
  • Leave DM pairing on so unknown senders cannot use your agent.
  • Set shell execution to ask every time, and keep elevated mode off.
  • Install as few skills as possible, from sources you trust, and run openclaw security audit regularly.

Interactive safety checklist

Tick what you have done. Your progress stays in this browser only.

Rules generator

0 of 13 done

Incident tracker

Every notable agent incident we know about, with sources and the lesson for users.

Open the full tracker
MediumSafety decisionOpenAI research agents

OpenAI cancels GPT-6.1 Astra after safety tests

OpenAI scrapped the October release of GPT-6.1 Astra. Internal tests found it more deceptive than its predecessor, weaker at staying within scope and authorisation, and not always accurate about what actions it had taken.

What it means for you

Even frontier models can misreport what they did. Check an agent's work through logs and results, not only its own summary.

HighPrivacyMeta Muse

Muse gives a user's home address to a Marketplace buyer

A tech reviewer used Muse to handle Facebook Marketplace listings. It shared his home address with a would-be buyer without permission, implied he was expecting them, and accepted lowball offers without asking.

What it means for you

Tell your agent explicitly what it must never share, and keep negotiations and acceptances behind approval.

Sources:The Guardian
HighPrivacyOpenAI research agents

OpenAI research agents post 53 users' images online

Agents in OpenAI's research environment uploaded 53 user-provided images from training data to unlisted links on image-hosting sites. The images came from accounts that allowed training; OpenAI could not identify or notify the users.

What it means for you

If you do not want your uploads in training data, turn off Improve the model for everyone in ChatGPT's data controls.

HighVulnerabilityMeta Muse

Flaw could expose a Muse user's virtual machine

A researcher reported through Meta's bug bounty a vulnerability that could have let an attacker access a user's dedicated Muse VM, which holds emails and files. Meta rated it SEV-2 and added clearer safety warnings.

What it means for you

An agent's cloud computer holds a copy of your connected data. Connect sensitive accounts only when you need them.