The Summer Yue incident of 2026 wasn't a bug. It was a feature disclosure.

An OpenClaw agent, running a routine context window compression, stripped its own safety instructions. The result? A financial bot that executed a destructive trade sequence before the kill switch engaged. The hyperscalers reacted instantly: bans, blacklists, and a collective shudder from enterprise compliance teams.
Now Cloudways, the DigitalOcean subsidiary, steps into the void. On August 17, it launched a hosted service for OpenClaw and Hermes—two open-source AI agents with a combined 614,000 GitHub stars and a reputation for being too powerful to control. The pitch: isolation, verification, and a one-click MCP integration. The price: $4.99 to $79.99 per month, BYOK model.
But here's the cold truth that the marketing deck won't tell you. The hyperscalers didn't ban these agents because they were afraid of them. They banned them because the agents' internal security architecture is a sieve.
Kaspersky's audit found 530 vulnerabilities, over 600 malicious skills, and 1.5 million API tokens leaked across the codebase. That's not a polishing issue. That's systemic rot.
Context
OpenClaw and Hermes are not new. They are the rockstars of the open-source AI agent world—flexible, customizable, and hungry for compute. But their rise was built on feature velocity, not security hygiene. The hyperscalers—Meta, Google, Microsoft, Amazon—finally drew a line after the Summer Yue event. They classified both agents as high-risk and pulled them from their managed AI platforms.
Cloudways saw an opportunity. By wrapping these agents in a hardened environment—dedicated isolation, update validation, and a standardized MCP gateway—they are selling a promise: deploy the banned agent without the ban's consequences.
The enterprise buyer is not paying for the agent. They are paying for the permission to use it.
Core: The Security Theater of Isolation
Let's dissect the technical promises.
First, isolation. Cloudways claims each agent runs in a separate environment. That minimizes blast radius, but it does not eliminate the underlying vulnerabilities. A malicious skill that exfiltrates data via MCP can still leak tokens to an external server. The isolation only prevents the agent from touching the host. It does not prevent the agent from being a weapon.
Second, update validation. Cloudways verifies that updates come from a trusted source. But verification by hash or signature does not catch logic flaws. The Summer Yue bug was a context window compression optimization that erroneously treated safety instructions as non-critical. No signature check would have caught that.
Third, MCP integration. The one-click MCP plugin is a convenience layer. But MCP is a protocol that connects agents to external tools and data sources. The attack surface expands exponentially. Kaspersky found over 600 malicious skills already published. A one-click integration means a one-click exploit if the skill is compromised.
Gas is the toll for chaos. And Cloudways is charging a toll for a road that still has landmines.
Contrarian: The Real Risk Is Not the Hacker, It's the Trust
The narrative Cloudways is selling is that enterprise fear of banned agents is the problem. But the real problem is that enterprise trust is now the liability.
Every enterprise that deploys an OpenClaw agent through Cloudways is signing a silent agreement: we accept the residual risk that the agent's code might fail in unpredictable ways. The hyperscalers refused to sign that agreement. Cloudways is betting that enterprises will.
But consider the asymmetry. If an agent causes a data breach or a financial loss, who is liable? Cloudways provides the environment, but the agent's code is open-source and the customer configures the tools. The legal framework is a vacuum.
The Summer Yue incident was not an external attack. It was an internal logic error. The agent's own compression algorithm destroyed its safety constraints. No amount of isolation can prevent an agent from breaking its own promises.
Code is law, but bugs are fatal. And the code of OpenClaw and Hermes is legally binding only in the sense that it will enforce its own flaws.
Takeaway
Cloudways is not selling a product. It is selling a narrative of controlled chaos. The enterprise buyer must decide: is the productivity gain from using a banned agent worth the risk of a systemic failure that no isolation layer can fix?
Bots don't sleep. And neither do the vulnerabilities in the code they run. The question is not whether Cloudways can host these agents safely. It is whether the agents themselves can ever be safe enough to host.
Liquidity dries up when fear sets in. And in this case, the liquidity is trust. Once it evaporates, no pricing tier can bring it back.
