2026-03-08

Fix LocalMediaAccessError: path-not-allowed (sending local images/attachments)

A practical checklist to fix OpenClaw LocalMediaAccessError: path-not-allowed when sending local files via message channels (e.g. Feishu).

Human Input

$You try to send a local image/file (e.g. a screenshot) via OpenClaw and get LocalMediaAccessError: path-not-allowed.

OpenClaw Output

A working configuration + a repeatable debugging checklist so local media sending succeeds safely.

Prerequisites (User config required)

You have OpenClaw installed and can run `openclaw` commandsYou know which channel you are sending to (Feishu/Telegram/etc.)You can edit your OpenClaw config safely

Fix LocalMediaAccessError: path-not-allowed

If you see an error like:

  • LocalMediaAccessError: path-not-allowed

…it means OpenClaw is blocking a local file path before it uploads/sends it.

This is good by default (it prevents accidental exfiltration of sensitive files), but it can be frustrating when you actually want to send screenshots.

When it happens

Typical triggers:

  • openclaw message send --media ~/xxx.png
  • a skill/tool produces a local file and then tries to attach it
  • you are sending through a channel that enforces a local path allowlist

Quick diagnosis (2 minutes)

  1. Confirm the actual path you’re trying to send.

    • Expand ~ yourself and check the full absolute path.
  2. Check whether the channel supports local media sending the way you expect.

    • Some channels require an upload step, and the gateway will enforce stricter path policies.
  3. Run with a “known safe” file

    • Put a test image into a dedicated folder like ~/openclaw-media/ and retry.

Fix checklist

1) Create a dedicated media folder

Pick a folder whose only purpose is “files that are allowed to be sent out”:

mkdir -p ~/openclaw-media

Move/copy your test image into it:

cp ~/Downloads/test.png ~/openclaw-media/test.png

2) Allowlist that folder (recommended)

Instead of allowing “any path”, allowlist only a controlled directory.

In your OpenClaw config, set the channel local roots to include the folder you just created.

Example concept (field names may differ per channel integration):

  • allow: ~/openclaw-media (and optionally a workspace output dir)
  • deny: everything else

3) Re-run the send

openclaw message send --media ~/openclaw-media/test.png

If it works, your config + path policy are fine.

4) If it still fails: common root causes

  • Config path is wrong (you set ~ but the runtime doesn’t expand it)

    • fix: use absolute path like /home/<user>/openclaw-media
  • You changed config but didn’t restart

    • fix: restart the gateway/service after config changes
  • You’re editing a different environment config

    • fix: confirm which openclaw.json is active
  • The channel implementation enforces stricter checks

    • fix: look for a dedicated localRoots/mediaRoots setting specific to the channel

Why we recommend “folder allowlist” (not any)

Allowing any local path is convenient but risky:

  • accidental leakage of private keys or tokens
  • sending files outside your intended project
  • ambiguous provenance of files produced by tools

A dedicated allowlisted folder keeps the UX good and the risk low.

Related

© 2025 OpenClawNews.org
All rights reserved.
This is an independent news site. Not affiliated with, endorsed by, or connected to OpenClaw. OpenClaw is a trademark of its respective owner.
Join the waitlist:

OC NEWS