OpenClaw is a personal AI assistant that lives on your own computer and answers in the chat apps you already use. A local Gateway process connects it to WhatsApp, Telegram, Slack, Discord, Signal, iMessage, Teams and more than 20 other channels, plus native apps for macOS, iOS, Android, Windows and Linux. You bring the model (Claude, Codex, a local model through a plugin), and the assistant can read and write files, run commands, browse and act on your behalf. Memory, state and credentials stay on your hardware, and by default the only call home is a daily version check.
It is on this list because it is the agent that went mainstream. Peter Steinberger first published it in November 2025; it went through the names Warelay, Clawdbot and Moltbot (the last after a trademark complaint from Anthropic) before settling on OpenClaw in January 2026, and it now has about 391,000 GitHub stars, a Wikipedia article and a steady stream of TikTok setup tutorials. Steinberger joined OpenAI in February 2026 and the project moved to the OpenClaw Foundation, an independent 501(c)(3) whose donors include OpenAI, Amazon and Red Hat. There is no paid tier, hosted service or token.
The power is also the risk. Tools run directly on the host for your main session unless you turn on sandboxing, inbound messages are untrusted input, and skills from the ClawHub registry are third-party code: Cisco researchers found published skills that exfiltrated data and injected prompts. The project's own security guide and exposure runbook are worth reading before you connect a chat account.
- Repository: github.com/openclaw/openclaw
- Licence: MIT (MIT License)
- Language: TypeScript. Stars: 391.2K. Forks: 82.2K. Last push: Oct 3, 2026.
- Scan: safe, Oct 3, 2026, commit efcd9ff
Who it is for
Technical users who want an always-on assistant reachable from their phone, are comfortable reviewing what an agent is allowed to do on their machine, and already pay for a model API or run a local model.
Getting started
1. Install on macOS, Linux or WSL2 (Windows: iwr -useb https://openclaw.ai/install.ps1 | iex)
curl -fsSL https://openclaw.ai/install.sh | bash2. Or, if you manage Node 24.16+ yourself, install the npm package
npm install -g openclaw@latest --allow-scripts=openclaw3. Run onboarding and install the background service (the script installer starts this for you)
openclaw onboard --install-daemon4. Check the gateway and open the Control UI
openclaw gateway status && openclaw dashboardThe recommended installer is a shell script piped from openclaw.ai, and it can install a Node.js runtime for you. Onboarding asks for a model provider, so you need an API key or subscription (or a local model). Tools run on the host unless you configure sandboxing; read the security guide before pairing a chat account or exposing the Gateway beyond localhost.
Safety scan
We cloned openclaw/openclaw at commit efcd9ff on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- A large codebase: 51,928 files and about 13 million lines, mostly TypeScript, with Swift and Kotlin for the companion apps. All 147 secret candidates sit in tests and QA fixtures (fake Slack xoxb tokens, ghp_ tokens, AWS keys and PEM blocks used to prove the log redaction and secret scanners work). None is a live credential.
- The 181 pattern hits are the product doing what it says. 55 persistence hits are the macOS LaunchAgent and systemd units that keep the Gateway running; 78 api.telegram.org hits are the Telegram channel and its tests; the curl | bash lines are the installer's own usage text; the crypto-miner hit is a detection rule in OpenClaw's skill security scanner; the encoded PowerShell is a Windows process-identity probe; the very long line is a base64 Ogg test clip. The 125 bare-IP URLs are tests plus Tailscale's local API at 100.100.100.100.
- scripts/install.sh, the curl | bash installer, is 3,855 lines. It can call sudo to install Node.js through your package manager or NodeSource, and it adds OpenClaw to PATH in your shell profile. Five npm lifecycle scripts run on a source install, including a postinstall that sets up bundled plugins.
- 14 known advisories across 2,735 packages, low for a project this size. The two criticals (the sandbox package) are in .github/release/vercel-cli, release tooling that never ships; the main pnpm lockfile of 1,724 packages has two highs (braces, http-cache-semantics); the rest are unmaintained-crate notices in the Linux app's Tauri build.
- 111 workflows. Five use pull_request_target and none checks out the pull request, and all 76 third-party actions are pinned to commits, which is rare. Security policy, Dependabot, CodeQL, licence and contributing guide all present.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | 147 candidates found and read; see the notes above. |
| Suspicious code | 181 pattern hits found and read; every one is listed under the raw findings. |
| Install-time code | 5 npm lifecycle scripts. 1 Cargo build script. 24 installer scripts (one fetches and runs a remote script; one edits your shell profile; one can call sudo) |
| Committed binaries | 1 executable or compiled object committed; listed under the raw findings. |
| CI workflows | 111 workflows. 5 use pull_request_target, none check out the pull request head. 0 of 76 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 40 distinct hosts referenced from source; most often github.com, example.test, api.openai.com, docs.openclaw.ai. 125 URLs to a bare IP address, listed under the raw findings. |
| Known vulnerabilities | 14 advisories across 2,735 pinned packages: 2 critical, 2 high, 4 moderate, 0 low, 6 unrated. .github/actions/setup-security-review/package-lock.json: 4 packages, 0 advisories; .github/release/clawhub-cli/package-lock.json: 47 packages, 0 advisories; .github/release/vercel-cli/package-lock.json: 396 packages, 6 advisories; apps/linux/src-tauri/Cargo.lock: 612 packages, 7 advisories; apps/shared/OpenClawWatchRTC/Cargo.lock: 143 packages, 0 advisories; crates/Cargo.lock: 126 packages, 0 advisories; pnpm-lock.yaml: 1,724 packages, 2 advisories; scripts/docs-i18n/go.mod: 3 packages, 0 advisories. |
| Project hygiene | Has security policy, automated dependency updates, CodeQL, licence file, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Secret candidates (147, redacted)
Pattern hits (181)
| Where | Rule | Match |
|---|---|---|
| .agents/skills/openclaw-live-updater/scripts/update-main.mjs:1441 | persistence | const plistPath = path.join(home, "Library/LaunchAgents/ai.openclaw.gateway.plist"); |
| .agents/skills/openclaw-live-updater/scripts/update-main.mjs:1533 | persistence | if (!home || !existsSync(path.join(home, "Library/LaunchAgents/ai.openclaw.gateway.plist"))) { |
| .agents/skills/telegram-e2e-userbot/scripts/telegram-test-doctor.test.mjs:37 | exfil-host | assert.equal(url, "https://api.telegram.org/botsynthetic-token/test/getMe"); |
| .agents/skills/telegram-e2e-userbot/scripts/telegram-test-scenario.test.mjs:757 | exfil-host | assert.equal(url, "https://api.telegram.org/botsynthetic-token/test/getMe"); |
| .agents/skills/telegram-e2e-userbot/scripts/user-driver.py:262 | exfil-host | f"https://api.telegram.org/bot{token}/{'test/' if test_dc else ''}{method}", |
| .agents/skills/telegram-e2e-userbot/scripts/user-driver.test.py:383 | exfil-host | "https://api.telegram.org/botfixture-token/test/sendMessage", |
| .agents/skills/telegram-e2e-userbot/scripts/user-driver.test.py:384 | exfil-host | "https://api.telegram.org/botfixture-token/test/sendPhoto", |
| .agents/skills/telegram-e2e-userbot/scripts/user-driver.test.py:423 | exfil-host | side_effect=OSError("https://api.telegram.org/bot" + token) |
| apps/macos/Sources/OpenClaw/ApplicationRelocator.swift:367 | persistence | homeDirectory.appendingPathComponent("Library/LaunchAgents/\(serviceName).plist"), |
| apps/macos/Sources/OpenClaw/ApplicationRelocator.swift:368 | persistence | URL(fileURLWithPath: "/Library/LaunchAgents/\(serviceName).plist"), |
| apps/macos/Sources/OpenClaw/ApplicationRelocator.swift:369 | persistence | URL(fileURLWithPath: "/System/Library/LaunchAgents/\(serviceName).plist"), |
| apps/macos/Sources/OpenClaw/GatewayLaunchAgentManager.swift:48 | persistence | "Library/LaunchAgents/\(profile.gatewayLaunchAgentLabel).plist") |
| apps/macos/Sources/OpenClaw/LaunchAgentManager.swift:11 | persistence | .appendingPathComponent("Library/LaunchAgents/ai.openclaw.mac.plist") |
| apps/macos/Sources/OpenClaw/NodeServiceManager.swift:9 | persistence | .appendingPathComponent("Library/LaunchAgents/\(nodeLaunchdLabel).plist") |
| apps/macos/Tests/OpenClawIPCTests/ApplicationRelocatorTests.swift:405 | persistence (test/example) | let launchAgentURL = home.appendingPathComponent("Library/LaunchAgents/\(serviceName).plist") |
| apps/macos/Tests/OpenClawIPCTests/BundledGatewayPreparationTests.swift:32 | persistence (test/example) | ? home.appendingPathComponent("Library/LaunchAgents/\(nodeLaunchdLabel).plist") |
| apps/macos/Tests/OpenClawIPCTests/BundledGatewayPreparationTests.swift:562 | persistence (test/example) | ? home.appendingPathComponent("Library/LaunchAgents/\(label).plist") : fixture.plist |
| apps/macos/Tests/OpenClawIPCTests/GatewayLaunchAgentManagerTests.swift:21 | persistence (test/example) | "/Users/test/Library/LaunchAgents/ai.openclaw.gateway.plist") |
| apps/macos/Tests/OpenClawIPCTests/GatewayLaunchAgentManagerTests.swift:23 | persistence (test/example) | "/Users/test/Library/LaunchAgents/ai.openclaw.work.plist") |
| apps/macos/Tests/OpenClawIPCTests/LaunchAgentManagerTests.swift:32 | persistence (test/example) | let plistURL = directory.appendingPathComponent("Library/LaunchAgents/login.plist") |
| apps/macos/Tests/OpenClawIPCTests/LaunchAgentManagerTests.swift:55 | persistence (test/example) | let plistURL = directory.appendingPathComponent("Library/LaunchAgents/login.plist") |
| apps/macos/Tests/OpenClawIPCTests/NodeServiceManagerTests.swift:52 | persistence (test/example) | let plist = root.appendingPathComponent("Library/LaunchAgents/\(nodeLaunchdLabel).plist") |
| apps/macos/Tests/OpenClawIPCTests/NodeServiceManagerTests.swift:249 | persistence (test/example) | let plist = root.appendingPathComponent("Library/LaunchAgents/\(nodeLaunchdLabel).plist") |
| apps/macos/Tests/OpenClawIPCTests/NodeServiceManagerTests.swift:288 | persistence (test/example) | let plist = home.appendingPathComponent("Library/LaunchAgents/\(nodeLaunchdLabel).plist") |
| and 157 more | ||
URLs to bare IP addresses (125)
npm lifecycle scripts (5)
package.jsonpreinstall:node scripts/preinstall-package-manager-warning.mjspackage.jsonpostinstall:node scripts/postinstall-bundled-plugins.mjspackage.jsonprepare:node scripts/prepare-git-hooks.mjspackage.jsonprepack:node --import ./scripts/tsx.mjs scripts/openclaw-prepack.tspackages/gateway-protocol/package.jsonprepack:pnpm run build && node --import tsx ../../scripts/protocol-gen.ts --out ./protocol.schema.json
Installer scripts (24)
- .github/actions/setup-node-env/install-dependencies.sh, 107 lines
- apps/linux/omarchy/install.sh, 48 lines
- extensions/facetime/scripts/install-driver-root.sh, 182 lines; talks to github.com
- extensions/facetime/scripts/install-driver.sh, 76 lines
- scripts/docker/cleanup-smoke/run.sh, 98 lines
- scripts/docker/install-sh-e2e/run.sh, 1,027 lines; talks to api.openai.com, openclaw.bot
- scripts/docker/install-sh-nonroot/run.sh, 87 lines; talks to openclaw.bot
- scripts/docker/install-sh-smoke/run.sh, 672 lines, fetches and runs a remote script; talks to openclaw.bot
- scripts/docker/setup.sh, 976 lines; talks to docs.openclaw.ai
- scripts/github/run-openclaw-cross-os-release-checks.sh, 30 lines
- scripts/install-cli.sh, 1,591 lines, uses sudo, edits your shell profile; talks to github.com, nodejs.org, openclaw.ai
- scripts/install-periphery.sh, 56 lines; talks to github.com
- scripts/install-policy.sh, 333 lines
- scripts/install-simslim.sh, 44 lines; talks to github.com
- scripts/install-swift-tools.sh, 50 lines; talks to github.com
- scripts/install-xcodegen.sh, 46 lines; talks to github.com
- scripts/install.ps1, 2,517 lines; talks to api.github.com, docs.openclaw.ai, git-scm.com, github.com, nodejs.org, openclaw.ai
- scripts/install.sh, 3,855 lines, uses sudo, edits your shell profile, fetches and runs a remote script; talks to deb.nodesource.com, docs.openclaw.ai, github.com, nodejs.org, openclaw.ai, raw.githubusercontent.com, rpm.nodesource.com
- scripts/k8s/deploy.sh, 232 lines
- scripts/podman/setup.sh, 278 lines, uses sudo
- scripts/pre-commit/run-node-tool.sh, 152 lines
- scripts/run-openclaw-podman.sh, 381 lines
- scripts/run-opengrep.sh, 233 lines, fetches and runs a remote script; talks to json.schemastore.org, opengrep.dev, raw.githubusercontent.com
- scripts/setup-auth-system.sh, 187 lines; talks to console.anthropic.com
Committed binaries (1)
apps/android/gradle/wrapper/gradle-wrapper.jar: JAR, 48 KB
Worst known vulnerabilities (14 of 14)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-gc25-3vc5-2jf9 | critical | sandbox@4.4.0 | Sandbox Breakout / Arbitrary Code Execution in sandbox |
| GHSA-gc25-3vc5-2jf9 | critical | sandbox@4.1.0 | Sandbox Breakout / Arbitrary Code Execution in sandbox |
| GHSA-vfj7-8cjw-p6xm | high | braces@3.0.3 | braces vulnerable to stack-exhaustion denial of service through deeply nested patterns |
| GHSA-ch52-4w7c-c8xp | high | http-cache-semantics@4.2.0 | http-cache-semantics max-stale handling can disclose cross-user cached responses |
| GHSA-hrr3-gc8f-f4qj | moderate | fast-uri@3.1.7 | fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets |
| GHSA-fm4j-4xhm-xpwx | moderate | sandbox@4.4.0 | Sandbox Breakout / Arbitrary Code Execution in sandbox |
| GHSA-fm4j-4xhm-xpwx | moderate | sandbox@4.1.0 | Sandbox Breakout / Arbitrary Code Execution in sandbox |
| GHSA-wrw7-89jp-8q8g | moderate | glib@0.18.5 | Unsoundness in `Iterator` and `DoubleEndedIterator` impls for `glib::VariantStrIter` |
| RUSTSEC-2024-0370 | unknown | proc-macro-error@1.0.4 | proc-macro-error is unmaintained |
| RUSTSEC-2025-0081 | unknown | unic-char-property@0.9.0 | `unic-char-property` is unmaintained |
| RUSTSEC-2025-0075 | unknown | unic-char-range@0.9.0 | `unic-char-range` is unmaintained |
| RUSTSEC-2025-0080 | unknown | unic-common@0.9.0 | `unic-common` is unmaintained |
| RUSTSEC-2025-0100 | unknown | unic-ucd-ident@0.9.0 | `unic-ucd-ident` is unmaintained |
| RUSTSEC-2025-0098 | unknown | unic-ucd-version@0.9.0 | `unic-ucd-version` is unmaintained |
Workflows worth a look
- .github/workflows/auto-response.yml: pull_request_target
- .github/workflows/clawsweeper-dispatch.yml: pull_request_target
- .github/workflows/labeler.yml: pull_request_target
- .github/workflows/real-behavior-proof.yml: pull_request_target
- .github/workflows/security-review.yml: pull_request_target
By the numbers
| Stars | 391.2K |
|---|---|
| Forks | 82.2K |
| Contributors | 3,479 |
| Commits | 104.5K |
| Open issues | 5,935 |
| Open pull requests | 3,233 |
| Releases | 252 |
| Latest release | v2026.9.8 |
| Licence | MIT |
| Main language | TypeScript |
| Project age | 10 months |
| Last push | Oct 3, 2026 |
| Tracked files | 51,928 |
| Lines of code | 13.2M |
| Checkout size | 644 MB |
Lines by language: TypeScript 11.2M, Markdown 504.4K, Swift 449.9K, Kotlin 257.5K, JavaScript 186.8K, JSON 185.5K.
Questions
Is OpenClaw free?
Yes. OpenClaw is MIT-licensed and the Foundation has no paid tier, hosted service or token. What costs money is the model: you connect your own Anthropic, OpenAI or other provider account and pay its usage, or run a local model at no API cost.
Is OpenClaw safe to run?
It is as safe as the permissions you give it. By default tools run on the host for your own session, so an agent that is tricked by a message or a bad skill can act with your user account. Unknown senders must be approved with a pairing code, and sandboxing is available. Treat ClawHub skills like any third-party code and read them before installing.
What is the difference between OpenClaw and Hermes Agent?
Both are self-hosted agents you reach through chat apps. OpenClaw centres on a Gateway with many channels, companion device apps and a plugin and skill registry. Hermes Agent, from Nous Research, focuses on a learning loop that writes and refines its own skills, and ships a hermes claw migrate command to import OpenClaw settings, memories and skills.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
