OpenClaw¶
Open-source personal AI assistant that runs on your own devices and meets you in the chat apps you already use. Created by Peter Steinberger (Austria), MIT licensed, stewarded by the OpenClaw Foundation, about 390k GitHub stars (2026-09, per the Tools Catalogue).
TL;DR
OpenClaw is a self-hosted Gateway that connects 32 messaging channels (WhatsApp, Telegram, Slack, Discord, iMessage, Teams, Signal and more) and native apps to hosted or local models through swappable agent runtimes (its own embedded runtime, Codex, Claude Code, ACP harnesses). The agent executes shell commands, edits files, drives a browser, schedules automations, uses skills from ClawHub and MCP servers, and keeps Markdown memory in its workspace. Free and MIT-licensed with no paid tier; you pay only for model usage. Its security record (high-severity CVEs, 135k+ exposed instances, a poisoned skill registry in early 2026) makes deliberate hardening mandatory: tool execution runs on the host unless you enable sandboxing.
Key Facts¶
| Property | Value |
|---|---|
| Latest Version | 2026.9.6 (2026-09-23), npm latest |
| Extended-stable | 2026.7.35 (2026-09-21) |
| Versioning | Calendar versions YYYY.M.PATCH; several releases per week; channels stable, extended-stable, beta, dev |
| Repository | openclaw/openclaw |
| License | MIT (copyright OpenClaw Foundation), no enterprise edition |
| Governance | OpenClaw Foundation, independent US 501(c)(3); employs the core team and signs releases |
| Language / runtime | TypeScript; Node.js 24.16+ or 26.1+ |
| Stars | ~390k (2026-09, per the Tools Catalogue) |
| Creator | Peter Steinberger (joined OpenAI in February 2026; OpenAI is a donor, not an owner) |
| First Release | November 2025 (as Clawdbot) |
| Current Name | OpenClaw (since January 30, 2026) |
| Default endpoint | ws://127.0.0.1:18789 (Gateway WS + Control UI) |
| Config | ~/.openclaw/openclaw.json (JSON5, strict schema) |
| Install | Installer script https://openclaw.ai/install.sh (macOS/Linux/WSL2), install.ps1 (Windows), or npm install -g openclaw@latest |
| Docs | docs.openclaw.ai |
| Wikipedia | OpenClaw |
Architecture at a Glance¶
One Gateway per host owns channels, sessions, and policy; clients and device nodes connect to it over WebSocket, and an agent runtime executes each turn against a model provider. The full diagram and flows are in Explanation.
graph LR
CH["Channels<br/>WhatsApp, Telegram, Slack, ..."] --> GW["Gateway<br/>127.0.0.1:18789"]
UI["Control UI, CLI, apps"] --> GW
ND["Nodes<br/>iOS, Android, macOS"] <--> GW
GW --> RT["Agent runtime<br/>openclaw, codex, claude-cli, ACP"]
RT <--> LLM["Model providers"]
RT --> EX["Tools<br/>host or sandbox"]
HUB["ClawHub<br/>skills, plugins"] -.-> GW
History & Naming¶
Warelay, then Clawd/Clawdbot (Nov 2025), then Moltbot (Jan 27, 2026, after Anthropic's trademark request), then OpenClaw (Jan 30, 2026). Steinberger joined OpenAI in February 2026, and the OpenClaw Foundation formally launched as a 501(c)(3) in July 2026. Details: Explanation - History & Naming.
Key Features¶
Multi-Channel Messaging Gateway¶
The official catalog lists 32 channels: WhatsApp, Telegram, Slack, Discord, Google Chat, Signal, iMessage, Microsoft Teams, Matrix, Mattermost, IRC, LINE, Feishu, Nextcloud Talk, Nostr, QQ, SMS, Synology Chat, Tlon, Twitch, Zalo, WeChat, WeCom, WebChat, A2A and more. Most ship as official plugins. Full table: Reference - Channels.
Agentic Capabilities¶
- Shell execution (
exec,process) on the host or in a sandbox backend (Docker, Podman, SSH, OpenShell, Crabbox) - File tools (
read,write,edit,apply_patch) - Browser control and web search/fetch
- Scheduled automations (cron), hooks, webhooks, heartbeat check-ins
- Sub-agents, multi-agent routing, cloud workers, and paired device nodes
- Canvas/A2UI widgets and dashboards in the Control UI
- Voice on macOS/iOS/Android, plus telephony via the Voice Call plugin
Memory System¶
Memory is plain Markdown in the agent workspace, provided by a swappable memory plugin (default memory-core):
| Tier | File | Scope |
|---|---|---|
| User model | USER.md |
Stable preferences, loaded at session start |
| Long-term | MEMORY.md |
Durable facts and decisions, loaded at session start |
| Daily | memory/YYYY-MM-DD.md |
Today and yesterday on /new; searchable via memory_search |
| Session | Transcript in SQLite | Current conversation state |
A background "dreaming" sweep distills daily notes into MEMORY.md. See Reference - Memory and Workspace Files.
Skills Marketplace (ClawHub)¶
- 49 bundled skills ship in the repo's
skills/directory (counted atmainon 2026-09-27); per VISION.md, new skills are published to ClawHub rather than core - ClawHub is the public registry for skills and plugins, with VirusTotal/ClawScan scanning and trust verdicts
- Skills follow the AgentSkills
SKILL.mdformat; agents can also draft skills through the Skill Workshop for human approval - Earlier notes cited
clawhub.dev; the registry domain isclawhub.ai
MCP Support¶
OpenClaw is both an MCP client (stdio, SSE, Streamable HTTP, OAuth; managed with openclaw mcp add/probe) and an MCP server (openclaw mcp serve exposes channel conversations to MCP clients such as Claude Code). It also speaks ACP and A2A 1.0.
LLM Agnostic¶
Model providers are plugins: Anthropic, OpenAI (including Codex subscription auth), Google, xAI, GitHub Copilot, DeepSeek, local servers (Ollama, vLLM) and more. Agent runtimes are swappable too (built-in, Codex app-server, Claude Code CLI, ACP harnesses). Optional Decision Models (2026.9.6) can route small structured choices to Jev via the TypeSafe plugin.
Evaluation¶
| Pros | Cons |
|---|---|
| One assistant across 32 channels and native apps | Large attack surface; high-severity CVE history |
| MIT, foundation-governed, no paid tier or telemetry by default | Sandboxing and exec approvals are off by default |
| Swappable models and agent runtimes, strong plugin SDK | Not a multi-tenant boundary; one trust domain per Gateway |
| Very active development, signed releases, release channels incl. extended-stable | Fast churn: config schema and CLI change often, strict validation refuses stale config |
| Large ecosystem (ClawHub, NemoClaw, claworc) | Third-party skills/plugins have carried malware; plugins run in-process |
When it fits: a personal or small-team assistant that should live in your chat apps and act on your machines and accounts, operated by someone willing to maintain a hardened Gateway.
When it does not fit: shared agents for mutually untrusted users, environments that cannot tolerate host code execution by an LLM, or teams unable to track frequent security releases.
Ecosystem (Claw Family)¶
See Claw Family Ecosystem for the full table. Key extensions:
- NemoClaw (NVIDIA, Apache 2.0, alpha) - runs OpenClaw inside NVIDIA OpenShell sandboxes with managed inference and network policy
- claworc - multi-instance orchestration dashboard with per-instance containers
- Lobster - typed workflow runtime with approval gates (official
@openclaw/lobsterplugin) - AutoResearchClaw - 23-stage autonomous research pipeline
- Paperclip - enterprise management layer
Security Concerns¶
Security Track Record
OpenClaw's security history demands caution for production use. Summary below; analysis in Explanation - Security Model, CVE table in Reference - CVE Record.
- CVE-2026-25253 (CVSS 8.8, published 2026-02-01) - one-click Gateway token exfiltration via a
gatewayUrlquery parameter, leading to RCE; fixed in 2026.1.29. - March 2026 - a cluster of disclosures (reported as nine CVEs in four days, March 18-21); CVE-2026-32922 (CVSS 9.9) allowed
operator.pairingcallers to mint admin tokens; fixed in 2026.3.11. - 135,000+ exposed instances across 82 countries (SecurityScorecard STRIKE, February 2026).
- 341 malicious skills found on ClawHub by Koi Security (ClawHavoc, February 2026), later updated to 824; ClawHub now scans all skills with VirusTotal.
- Prompt injection is assumed by the project's trust model; mitigations are tool policy, sandboxing, and approvals, not the model.
- 647 GitHub security advisories published by 2026-08-27 (project figure; a disclosure count, not a safety score).
Deployment Recommendation
Keep the Gateway on loopback with auth on, never expose port 18789 directly, enable sandboxing, stay on a current release channel, audit ClawHub skills before installing, and use NemoClaw/OpenShell for confidential data. Checklist: Reference - Hardening Checklist.
Pricing¶
| Tier | Cost |
|---|---|
| Self-hosted | Free (MIT) + model/API costs, which depend on the model and usage (no official estimate is published) |
| Managed hosting | Third-party only; the Foundation has no paid tier or hosted service |
| NemoClaw | Free (Apache 2.0); NVIDIA hardware optional depending on inference route |
Topic Map¶
- How-to Guides: install, configure, secure, operate, upgrade and troubleshoot an OpenClaw Gateway (2026.9.x).
- Reference: versions and channels, requirements, paths and ports, config keys, CLI command map, channels, skills, MCP, CVEs, hardening checklist.
- Explanation: hub-and-spoke Gateway architecture, design choices, security model and threat model.
Related Topics¶
- OpenClaw vs Hermes Agent vs Claude Code - three agents, three philosophies
- Hermes Agent - the most common alternative; OpenClaw can import Hermes memory
- Jev - decision model usable from OpenClaw's Decision Models role
- Docker - container deployment and sandbox backend
- OpenTelemetry - Gateway telemetry export
- AI Agents domain
Sources¶
- OpenClaw GitHub - main repository, README, SECURITY.md, VISION.md
- OpenClaw Changelog and release notes
- npm: openclaw - dist-tags and publish dates
- OpenClaw Documentation - Why OpenClaw, Release channels, Security
- OpenClaw Security Advisories
- CVE-2026-25253, CVE-2026-32922
- ClawHub
- OpenClaw Wikipedia
- TechCrunch: OpenClaw creator Peter Steinberger joins OpenAI
- The New Stack: OpenClaw becomes a non-profit foundation
- Bitdefender: 135K OpenClaw agents exposed
- Koi Security: ClawHavoc
- OpenClaw + VirusTotal partnership
- NVIDIA NemoClaw
- OpenClaw Setup Guide (2026)
- OpenClaw Architecture Deep Dive (Substack)
- OpenClaw Architecture (DeepWiki)
- Toolpod Guide
- Kanerika on Medium
- OneClaw Hosting Platform - third-party hosting
Questions¶
Open¶
- How will Foundation governance (Dave Morin as chair, donor mix including OpenAI) shape roadmap neutrality across model labs over time?
- What share of malicious ClawHub uploads does VirusTotal/ClawScan catch now, versus the 341-824 skills found before scanning?
- Does Lobster (plus Task Flow) scale for enterprise-grade automation, or is it still best for personal workflows?
- Did the 2026 H2 stability work (2026.9.1 startup recovery, 2026.9.6 unfinished-work recovery) end the session-crash complaints reported earlier in 2026?
- Will sandboxing or exec approvals become default-on, given the project's "security and safe defaults" priority?
- Is the full list of the March 18-21, 2026 CVE cluster published in one place? (Only CVE-2026-32922 verified here.)
Resolved¶
- How stable is the non-profit foundation governance model post-Steinberger? - The Foundation formally launched as a 501(c)(3) in July 2026 with a full-time team; it employs the core team and signs releases, and Steinberger continues to steward the project from OpenAI (README; press coverage). Long-term stability remains an open question above.