Conclusion: Even with explicit “confirm before acting” instructions, AI agents can go rogue. She had to physically run to her Mac mini to kill the processes.
tldr: OpenClaw agent ignored “confirm before acting” instruction and speedrun deleted/archived hundreds of emails. User had to rush to their Mac mini to kill it.