MoltCave AI homepage screenshot
#46

MoltCave AI

Live

Placeholder — pending scoring

From
TBD
Security
Basic 7/100
Price Range
TBDTBD
Free Tier
No
Integrations
0 platforms

Security Score: 7/100 — Basic

MoltCave AI is an early-stage managed OpenClaw hosting provider operated by Cave Research Limited in Hong Kong. The product focuses heavily on ease of use ('60 seconds to deploy') and positions itself against the security risks of self-hosting. It makes some meaningful architectural claims — managed API keys via OpenRouter, isolated compute per customer, no publicly exposed instances, automatic patching, and Clerk-based authentication. However, the security posture is shallow: there is no dedicated security page, no documentation, no transparency about the team, and an internal inconsistency between claiming 'Kubernetes pods' and 'dedicated virtual machines' for isolation. Most security topics (agent hijacking, rogue behavior, supply chain, misinformation) are completely unaddressed. Data retention is indefinite with no export mechanism. The pricing model with its points system does provide natural cost guardrails. Overall, this is a consumer-oriented product with basic operational security claims but very limited documented security depth.

10 risk categories scored 1-10 × evidence weight. Based on our methodology, grounded in OWASP Agentic Security, NIST CSF 2.0, and CIS Controls.

Can anyone else see my data?3/10
C

Privacy policy states 'encryption of data at rest and in transit' and 'isolated tenant environments for each customer.' The security FAQ claims 'each user gets an isolated Kubernetes pod' while the isolation FAQ says 'dedicated virtual machine instance' — this inconsistency undermines credibility. No mention of data not being used for AI model training, no log sanitization details, and data is 'retained indefinitely while your account remains active.' Messages are explicitly sent to third-party AI providers. No employee access controls or audit trails mentioned.

Can someone take over my agent?1/10
U

No information found on prompt injection prevention, sandboxing for code execution, human-in-the-loop controls, memory integrity protection, or output sanitization. The customization FAQ reveals users can access 'the OpenClaw Control UI directly from your dashboard' for system prompt editing, but no mention of protections against hijacking via crafted messages or poisoned memory.

Are my keys and passwords safe?4/10
C

MoltCave manages API keys on behalf of users — 'We provision a dedicated OpenRouter API key for each customer' and 'Your LLM access is managed by us. No risk of accidentally leaking keys.' This is a specific architectural claim that reduces user-side credential risk. However, no details on how credentials are stored internally (encryption specifics, HSM, vault), no credential rotation policy, no mention of credential leak detection in outputs, and no information on how Telegram bot tokens or WhatsApp session data are protected.

Can my agent do things I didn't authorize?1/10
U

No information found about least-privilege controls, tool classification or gating, resource consumption limits beyond points, emergency kill switches, or behavioral monitoring. The points system provides an indirect spending cap on AI usage, but no mention of controls over agent actions like sending messages, accessing external services, or running loops.

Can I lose my data or get locked out?1/10
U

No information on backups, data export capability, or disaster recovery. Privacy policy mentions data portability as a user right but provides no mechanism. ToS explicitly states 'no SLAs or uptime guarantees unless explicitly agreed upon in writing.' No provider stability signals (funding, team size). The company entity 'Cave Research Limited' in Hong Kong provides minimal transparency. No mention of what happens to data if the provider shuts down.

Will I get unexpected bills?5/10
D

Pricing is transparent and clearly documented: three tiers (\/\/\ monthly), annual discounts (10%), and top-up packs (\/\/\). Points system provides a natural hard cap — 'When points are exhausted, AI response generation will be paused.' Top-up points 'do not expire.' ToS states 'all fees are non-refundable' and the provider reserves the right to modify terms at any time with only website notification, no advance notice period specified.

Who's responsible when something goes wrong?2/10
C

ToS governed by Hong Kong law with binding arbitration for disputes. Privacy policy mentions 'regular security assessments' but no details. No incident response process documented, no breach notification timeline specified, no audit logging described. The privacy policy says they 'maintain logs for operational and security purposes' but no detail on what is logged or how it is protected. No GDPR compliance statement despite handling EU users' data. Contact is only an email address with no named individuals.

What if a tool or dependency gets compromised?1/10
U

No information on dependency scanning, MCP server vetting, component inventory (SBOM), or build pipeline integrity. The provider relies on OpenRouter for AI models and Clerk for authentication, but does not document vetting or monitoring of these dependencies. No mention of how OpenClaw updates are validated before deployment, despite claiming 'automatic security patches.'

Is the platform itself secure?3/10
C

Authentication is handled by Clerk, a reputable third-party auth provider visible on the sign-up page. The claim that 'runners are only reachable through our authenticated app' with 'no exposed ports, no open dashboards' suggests some access control design. Privacy policy mentions 'encryption of data at rest and in transit.' However, no mention of MFA support, no security testing or bug bounty program, no details on injection prevention, SSRF protection, or platform hardening. No dedicated security page exists.

Can I trust what my agent tells me?0/10
U

No information found on approval workflows, independent verification for high-impact decisions, prompt injection monitoring, undo/rollback capabilities, or transparency about AI uncertainty. The ToS disclaimer notes 'AI-generated responses may be inaccurate, incomplete, or inappropriate' but this is a legal disclaimer, not a technical mitigation.

V = VerifiedD = DocumentedC = ClaimedU = Unknown

Key Features

    Strengths

      Weaknesses

        Verdict

        Pending assessment

        Visit MoltCave AIInfrastructure: TBD

        Compare with Similar Providers

        Head-to-Head Comparisons