Comment by azinman2
If it’s a local model, why would you care if it sees your messages or notes?
If it’s a local model, why would you care if it sees your messages or notes?
Because it is running with --dangerously-allow-all and can make HTTP calls to exfiltrate data.
It can also install arbitrary software.
https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
Note that nothing about that depends on it being a local or remote model, it was just less of a concern for local models in the past because most of them did not have tool calling. OpenClaw, for all the cool and flashy uses, is also basically an infinite generator for lethal trifecta problems because its whole pitch is combining your data with tools that can both read and write from the public internet.