Security is about the weakest link.
It doesn't matter if you lock the back door, if the front door is not only unlocked, not only wide open, but there's just no walls in the front at all, then that locked back door doesn't matter at all.
That's what it seems like to me when people say "I run MoltBot in a VM so it's safe."
Yes, but then you put all of your sensitive data into it!
It doesn't matter if it's in a VM if it has all of your data anyway.
The idea of "let's let people run OpenClaw in a VM" is hilarious to me.
Running in a VM is the least important part about making it safe.