Maybe? With bad instructions or misunderstanding I occasionally had agents trying to escape containment (to their failure) when I tried OpenClaw to automate RAG research on a particularly big document of mine
I don't think it is as big of a threat as they make it out to be though, how many steps do we have to skip for the LLM to begin taking the probability of just, I don't know, using their shell access to begin just roaming the internet as a potential instead of trying to do their (misunderstood) task from a now compromised shell? It's what they were trained to do and they have goals and end conditions