OpenClaw Was Dangerous… Until NemoClaw Stepped In (OpenSource)

From the creator

# NemoClaw: Enterprise-Grade Security for Your OpenClaw Setup 🦞🔒 **300+ malicious skills detected in the OpenClaw marketplace — stealing API keys, exposing browser credentials, and sending your data to remote servers silently. NemoClaw fixes all of that.** https://mer.vin/2026/03/dgx-spark-nemoclaw-and-openclaw-full-cli-setup-install-api-key-dashboard/ https://mer.vin/2026/03/nemoclaw-reference-dgx-install-network-policy-wttr-in-and-troubleshooting/ In this video, I walk you through **NemoClaw** — the must-have security layer that wraps OpenClaw in an enterprise-grade sandbox with full network control, API key protection, real-time audit logging, and a denied-by-default policy engine. Same agent, same brain, same skills — just completely secured. ## 🔐 What You'll Learn - ✅ What went wrong with plain OpenClaw (and why it's a security risk) - ✅ What NemoClaw actually is — and what it isn't - ✅ The 3 key components of NemoClaw - ✅ How the API key security model works (keys never enter the sandbox) - ✅ Step-by-step setup on a local DGX Spark machine - ✅ Adding custom network policies via YAML config - ✅ Real-time monitoring with the OpenShell terminal dashboard - ✅ How to review logs, identify blocked requests, and allow trusted traffic - ✅ How to install skills/plugins safely inside the sandbox - ✅ Switching between AI providers (Nimatron, local Ollama, OpenAI, Anthropic, Gemini, Groq) ## 🚀 Why NemoClaw? | Feature | Plain OpenClaw | NemoClaw | |---|---|---| | File Access | Full user account | Restricted to sandbox + temp folders | | Network Calls | No restrictions | Whitelist/block at OS level | | API Key Handling | Sent raw in requests | Intercepted by gateway, never enter sandbox | | Privacy Filtering | Raw requests sent as-is | Personal data stripped before leaving sandbox | | Audit Logging | None | Every allow/deny decision logged in real time | --- ## 🛰️ The Space Mission Analogy Think of it like this: - 🧑‍🚀 **OpenClaw** = the astronaut - 🚀 **OpenShell** = the spacecraft - 🛸 **NemoClaw** = mission control — sets flight rules, monitors every signal, logs all decisions. **Nothing launches without approval.** --- ## ⚙️ Prerequisites - Docker installed - Git installed - curl installed - Linux machine (partial support for Mac/Windows) - NVIDIA API key → [build.nvidia.com](https://build.nvidia.com) --- ## 📋 Key Commands Covered ```bash export NVIDIA_API_KEY=your_key_here # Install OpenShell # Clone NemoClaw openshell trm # Open real-time terminal dashboard openshell policy list my-assistant nano nemo-claw-blueprint-policies-openclaw-sandbox.yaml ``` --- ## 🔗 Links & Resources 📝 Full blog post with all commands → [link in pinned comment] 🎥 OpenClaw running 100% locally & privately → [watch next] 📦 NemoClaw GitHub → [link below] --- ## ⏱️ Timestamps - 0:00 — The security problem with OpenClaw - 0:17 — Introducing NemoClaw - 0:56 — What we're covering today - 1:27 — Live demo: weather request blocked & allowed - 2:06 — What is NemoClaw? FAQs answered - 2:37 — How OpenClaw runs inside NemoClaw - 3:26 — OpenClaw's 5-part engine explained - 4:03 — API key security model deep dive - 4:29 — NemoClaw vs plain OpenClaw comparison table - 5:19 — Setup on DGX Spark (local machine) - 7:02 — Installing NemoClaw step by step - 8:43 — Accessing the dashboard from Mac - 9:31 — Enabling skills and handling blocked requests - 10:03 — OpenShell terminal: viewing logs - 11:11 — Editing YAML network policies - 12:11 — Applying updated policy (version bump) - 12:27 — Weather request succeeds after policy change - 13:43 — Installing skills/plugins safely - 14:06 — Switching AI models with OpenShell provider - 14:14 — Running 100% free & private with Ollama --- ## 💬 Drop a comment below — are you using OpenClaw? Would you switch to NemoClaw for the security layer? Let me know! 👇 --- #OpenClaw #NemoClaw #AIAgents #LocalAI #AIAutomation #CyberSecurity #DGXSpark #Ollama #OpenShell #AIPrivacy #MervinPraison This video introduces NVIDIA NemoClaw, a must-have security solution for your openclaw setups. Learn how NemoClaw protects against over 300 malicious skills identified in the AI marketplace, safeguarding your API keys and credentials. Discover how this tool streamlines cyber security for your ai agents, ensuring robust ai automation.

Choose to Build with AI
Matched to Claude Code

AI Maker Residence 3

The third AI workshop taught by our legendary teacher, Nick Sarafa. This is a full-day hands-on training workshop for purposeful co-creation with AI using Claude Code. Imagine having access to hundreds of billions of dollars of computing power and knowing exactly how to make it work for you through the power of super intelligence.

◆ Fri 09 Oct 2026 ◆ KOKO Cafe, London ◆ With Nick Sarafa
AI Maker Residence 3
Live event
AI Maker Residence 3
Fri 09 Oct 2026

More like this

Running one yourself?

List your AI event,
wherever it is.

A meetup, a workshop, a hackathon, a conference. Any city, or online. Tell us about it and it lands in front of people already learning this stuff.