OpenClaw is an open-source (MIT) personal AI agent that runs on your own computer and is operated through the messaging apps you already use. It began as a project by developer Peter Steinberger and is now stewarded by the independent OpenClaw Foundation, a 501(c)(3) nonprofit. According to its GitHub repository it has more than 390,000 stars, and it connects to 20+ messaging services, with state, memory and credentials kept locally. It is model-agnostic, working with cloud models such as Claude as well as local ones, and costs nothing beyond the model tokens or hardware you supply.
Version 2.0 (tagged v2026.8.1, August 30, 2026) targeted teams: shared agent sessions with graded access, a rebuilt browser control UI, guided model setup, and wider sandboxing through Docker and Podman, role-enforced permissions and a team secret store. Coverage by The Register noted, however, that sandboxing and execution approvals remain opt-in, with a baseline that assumes one trusted operator and allows host-level commands.
The security history is the main caveat. Researchers reported a high-severity vulnerability (CVE-2026-25253), a malicious-skill campaign on ClawHub (Koi Security found 341 malicious skills among 2,857 audited), and scans finding tens of thousands of internet-exposed instances with unsafe settings. NVIDIA's NemoClaw sandbox, built to run OpenClaw more safely, also had its own disclosed flaw (CVE-2026-65105). The project is powerful and flexible, but it is best treated as expert-grade infrastructure rather than a consumer app. Compare managed alternatives such as Manus or Claude, or Hermes Agent for a similar open-source approach.
Key Benefits
- Own your data and stack: Everything runs on your hardware, with no vendor subscription and an MIT license.
- Meet it where you chat: Talk to the agent from WhatsApp, Slack, Telegram and other apps instead of a new interface.
- No model lock-in: Switch providers or run local models as pricing and quality change.
- Team features: v2.0 adds shared sessions and optional sandboxing for multi-user use.
Use Cases
- Personal assistant in your chat apps — Delegate tasks and reminders from the messenger you already use.
- Self-hosted automation — Run a private agent that uses your own files, accounts and tools.
- Coding and ops help for technical teams — Use shared sessions to watch or steer a running agent, with sandboxing enabled.
- Local-model experiments — Pair the agent with local models for privacy-sensitive workflows, ideally behind a sandbox.