Video summary
I Built an AI Agent That Hacks for Me | OpenClaw + Kali Linux
Main summary
Key takeaways
Overview
The video demonstrates a step-by-step build of an “AI hacker” agent using OpenClaw running on a cloud-based Kali Linux machine, controlled via chat—specifically Telegram. The goal is for the agent to execute cybersecurity tasks (e.g., scanning, OSINT, pentesting) on command and return results to the user on a mobile device.
Core concept / architecture
-
OpenClaw framework
- Installed on a computer so an AI model can control the machine (terminal + browser) and run tasks via deployed agents.
-
Chat-to-task workflow
- Instead of only answering questions, the AI generates a plan and then acts on the computer using installed tooling.
-
Kali Linux environment
- The Kali host provides access to common infosec/pentest tools, including:
- Nmap
- Metasploit
- The Harvester
- (and more)
- The Kali host provides access to common infosec/pentest tools, including:
Security + deployment approach (cloud setup)
- The system runs Kali + OpenClaw on an always-on cloud VM to isolate it from the user’s personal data.
- Uses SSH with an SSH key (with root login mentioned).
- In
sshd_config, it disables SSH password authentication:- Sets
PasswordAuthentication noso only the private key can authenticate.
- Sets
- Highlights cloud-exposure concerns, such as:
- Avoiding port forwarding
- Being careful about public accessibility (e.g., “fishing pages”)
- Making the service reachable globally without making it unsafe
Hostinger VM details (why/how)
- Hostinger is chosen because Kali can be launched easily.
- Plan comparison:
- The free tier (Amazon: ~2GB RAM) is too small for Kali/OpenClaw workloads.
- A plan with 8GB RAM (~$7/month) is selected (pricing/details can vary by usage/plan).
- A coupon is applied (e.g., “Z security”), then Kali Linux is launched.
OpenClaw installation and configuration
1) Install OpenClaw
- Installed via the GitHub recommended method.
- A note is mentioned that a single-command install reportedly broke due to updates.
2) Run onboarding wizard
The onboarding wizard includes prompts such as:
- Acknowledge risk:
- “Powerful and risky” because it can control the entire computer.
- Onboarding mode:
- Uses manual.
- Gateway:
- Kept local only (bound to loopback) for security.
- Workspace directory:
- Defaults to the suggested location.
- Model provider (“brain”):
- OpenRouter selected.
AI model (“brain”) via OpenRouter
- OpenClaw itself isn’t “smart” unless connected to an AI model.
- Uses OpenRouter, which:
- Claims access to hundreds of models (mentions 627)
- Requires only one API key to enable many model options
- Chooses Claude 4.6 Opus as best for agentic workflows.
- Mentions alternatives and tradeoffs:
- Rate limiting with some free models
- Possible cheaper options like:
- Gemini 3 Pro
- Kimi 2.5
- The setup flow includes creating an OpenRouter API key.
Messaging/control channels (Telegram focus)
- OpenClaw supports messaging “channels” so the agent behaves like a chat assistant.
- Telegram is preferred over WhatsApp:
- WhatsApp could risk using the user’s own WhatsApp account.
- Signal/Matrix are described as more friction-heavy (SIM/manual steps).
- Strategy emphasized:
- Prefer bot-based messaging for security and convenience.
Setup steps
- Create a Telegram bot using BotFather
- Provide the bot token to OpenClaw
DM access policy
- Uses an allow list so only the owner account can message the bot.
- Retrieves the user ID via a user info bot.
- Bot is configured to ignore everyone else.
Skills installation (ClawHub) + tooling behavior
- After initial “wake up,” the agent is treated like a “smart baby” until configured.
- Installs agent skills from a “skill hub,” with an explicit warning that some skills can be malicious:
- Stealth browser skill
- Intended to bypass CAPTCHAs / Cloudflare / bot detection
- Security caveat included:
- About 12% of skills on ClawHub were claimed malicious
- Skills should be validated/scanned before use
- Tavily Search Pro skill
- Improves AI-oriented searching
- Requires a Tavily API key
- Stealth browser skill
Agent rules / prompt
-
OpenClaw is given a detailed instruction file (e.g.,
agent.md) including rules such as:- Use Kali cloud tools
- Use Tavily for searches
- Fall back to stealth browser if needed
- If an API key is required and missing, avoid asking the user—use alternatives where possible
- Do not execute code from the internet (mitigates prompt injection)
- Prefer installing tools from official Kali/Debian repositories
- Be proactive and share instructions to sub-agents
Demonstrations / use cases (results shown)
1) Location-based CCTV discovery
- User provides:
- Location (e.g., Temple Bar, Dublin)
- Request for CCTV cameras and a view link
- Agent returns a list; clicking is claimed to show “100% correct” camera proximity.
2) Multi-sub-agent workflow
-
Demonstrates spawning multiple sub-agents simultaneously:
- OSINT sub-agent about a person (e.g., Zaid Sabbahi)
- Includes social connections, phone numbers, leaked/breached accounts, addresses, etc.
- Website security testing sub-agent
- Target mentioned: zshacks.com
- OSINT sub-agent about a person (e.g., Zaid Sabbahi)
3) Automatic vulnerability hunting using another framework (Strikes)
- Agent spawns a sub-agent that installs/configures Strikes (an agentic framework for website hacking/bug hunting).
- Claims Strikes setup is mostly automatic:
- Reuses the existing OpenRouter key
- Selects a model (mentions free DeepSeek via OpenRouter)
- Outputs a “quick scan” report with claims such as:
- SQL injection findings on login and search pages
- Claims it “cracked three passwords instantly” and extracted admin credentials
- Recon steps include:
- Nmap
- subdomain enumeration
- directory/path discovery
- Exploitation/reproduction details plus extracted usernames/passwords
Reviews / warnings / guidance mentioned
- High risk: OpenClaw has full computer control; users must explicitly confirm.
- Operational security recommendations:
- SSH key-only login
- Keep gateway local/loopback
- Use allow-list DM policy
- Warning about malicious skills on ClawHub:
- Scan/verify skills before installing
- Avoid:
- Executing code from the internet
- Installing tools from untrusted sources
Main speakers / sources
- Ace from CC Security (main speaker)