OpenClaw blew up because it moved high-permission local agents into chat apps people already use. The article gives two hard numbers: 12% of third-party skills contained malicious code, and the $CLAWD scam pulled in $16 million. That alone tells me this is not a settled product category. It is a distribution event outrunning product maturity.
I mostly buy the article’s main frame. OpenClaw did not win on raw model capability. It won on interface and reach. Over the last year, tools like Cursor, Claude Code, Codex CLI, and OpenCode already normalized the core loop: read files, edit code, run commands, call tools, keep iterating. The bottleneck was access. Those systems lived in IDEs, terminals, repos, and working directories. Non-technical users never entered that environment. OpenClaw dropped the same class of behavior into Slack, WhatsApp, and Feishu, where the learning curve is close to zero. That pattern matches how “search + reasoning” products spread earlier: the shock came from wider exposure, not from a sudden leap over every competitor.
Where I part ways with the hype is chat as the main operating surface. The article names the right problems: linear conversation, low information density, low observability. I think those are structural limits, not rough edges. Ask an agent to touch 20 files, compare two branches of work, generate a long memo, then explain why it changed a config, and the chat window starts fighting the task. Cursor stuck because the model was only half the story; the other half was diffs, file trees, terminal logs, tool traces, and visible state. Chat is good for intent capture. It is weak for process-heavy work. I haven’t personally run OpenClaw, so I’m staying inside the article’s evidence here, but nothing in the snippet suggests that tension is solved rather than temporarily hidden by novelty.
The article is stronger when it shifts from “install this thing” to “copy these design choices.” Unified entry, file-based memory, composable skills: that is the durable part. File-based memory especially matters. Manus made a similar context-engineering argument last year, and a lot of teams building agent memory eventually drifted back from pure vector retrieval to editable markdown or repo-native files because humans can inspect them and version them. OpenClaw’s SOUL.md / USER.md / MEMORY.md layering is not a new invention, but packaging it for mass users is smart. My pushback is the same one the article hints at: if heartbeat jobs can summarize, rewrite, and forget, then this is drifting memory, not a dependable knowledge base. Teams that care about knowledge assets want docs they can cite, diff, lock, and audit. They do not want an auto-maintained summary silently becoming the new source of truth.
I’m also more conservative than the article on skills. Yes, more tools raise the ceiling, and composition creates step-function gains. But plugin ecosystems almost always let the growth curve outrun the safety curve. A 12% malicious-code rate is not a footnote. It is a sign that the ecosystem is already contaminated. Simon Willison’s “lethal trifecta” fits almost too cleanly here: access to private data, exposure to untrusted content, and ability to communicate or act externally. Add local command execution and you have a nasty blast radius. I could not verify the article’s 12% audit methodology from the snippet, and the body does not disclose sample size or scanning conditions. So I won’t overstate the precision of that number. Even cut in half, the problem is severe enough to kill any default-open skills marketplace for serious use.
There’s another context point the article doesn’t really develop. Over the last year, every serious attempt to bring agents into enterprises has moved toward tighter permission models, clearer audit trails, and approval gates. Microsoft’s Copilot stack did this. OpenAI’s enterprise agent products have leaned harder into connectors, policies, and workspace controls instead of “just give it shell.” The reason is simple: once distribution gets broad, the accident surface expands with it. OpenClaw wins today on convenience and familiarity. If it ever tries to become a real enterprise layer, it will be pushed toward sandboxed tools, explicit approvals, and far better observability. At that point it starts looking less like a chat bot and more like a hybrid of desktop agent and enterprise automation.
So my read is pretty direct: don’t treat OpenClaw as the end state. Treat it as a signal amplifier. It shows that mainstream users are ready for high-permission agents if the entry point feels familiar. It shows that memory has to land in editable, file-like structures or it turns into black-box drift. And it shows, again, that plugin ecosystems rot fast when safety trails adoption. The title says it “suddenly” caught fire. I don’t think it was sudden at all. Model quality, tooling, lower inference costs, and user expectation were already in place. What the market lacked was a shell that removed the intimidation factor. OpenClaw supplied the shell. A shell is not a moat.