OpenClaw
AtivoSelf-hosted, MIT-licensed AI assistant you message from the chat apps you already use
OpenClaw is a credible free way to run a personal AI agent on your own hardware: MIT licensed, no paid tier, reachable from 29 chat channels, and able to browse, read and write files and run shell commands. Conditional because that reach is the risk: its docs disclaim it as a boundary between mutually adversarial users, and Unit 42 found malicious ClawHub skills, warning that installing a skill grants complete control over the agent's identity. Right for technical users who will harden and audit it; wrong for unmanaged shared deployments.
A self-hosted gateway routes chat messages to an AI agent that browses the web, reads and writes files, and runs shell commands
É adequada para ti?
Bom para
- Running a personal AI agent on hardware you control: the README says state, memory and credentials live on your hardware, and the site says state lives on your machine, not a vendor cloud
- Talking to an agent from apps you already use, with openclaw.ai naming WhatsApp, Telegram, Discord, Slack, Signal and iMessage among its 29 channels, in DMs and group chats
- Choosing your own model provider, from Anthropic, OpenAI, Google and DeepSeek to local runtimes such as Ollama, LM Studio, llama.cpp and vLLM
- Zero software cost: MIT licensed, stewarded by an independent 501(c)(3), with no paid tier, hosted service or token
- Hands-on computer errands, which OpenClaw's site describes as browsing the web, filling forms, reading and writing files and running shell commands
- Starting from restrictive defaults: on a regular host install the gateway binds to loopback, most channels answer unknown DM senders with a pairing code, and group access is allowlisted, with an openclaw security audit command to detect drift
Não recomendado para
- Sharing one agent or gateway between people who do not trust each other: the security docs state OpenClaw is not a hostile multi-tenant security boundary for mutually adversarial users
- Installing community skills without auditing them: Unit 42 identified five malicious skills on ClawHub that had not been blocked between February and May 2026, and warns that installation results in complete control over the agent's identity; OpenClaw deleted all five after Unit 42 reported them
- Deployments nobody will keep patched: CVE-2026-25253, rated 8.8 High, let versions before 2026.1.29 take a gatewayUrl from a query string and open a WebSocket connection without prompting, sending a token
- Non-technical users: installation runs through a shell script, PowerShell or npm and requires Node 24.16+ or 26.1+
- Anyone who wants a vendor-hosted service, since the README states the project has none
A nossa experiência
Preços
Código aberto- No subscription, no hosted tier, no token
- Bring hosted, subscription-backed, gateway or local models
- Uses an API key from your chosen model provider
- Prepared cloud workers incur provider running-machine charges until deleted
Receitas de fluxo de trabalho
Install and harden a personal gateway
Get OpenClaw running on your own machine before connecting anyone else
- Install with curl -fsSL https://openclaw.ai/install.sh | bash on macOS, Linux or WSL2, iwr -useb https://openclaw.ai/install.ps1 | iex on Windows, or npm install -g openclaw@latest --allow-scripts=openclaw (omit --allow-scripts on npm 11.15 and earlier)
- Add an API key from your chosen model provider
- Read the security guide, exposure runbook and sandboxing guide before connecting other users
- Apply a hardened baseline config that keeps the gateway local, paired and tool-restricted
- Run openclaw security audit to check the deployment has not drifted
Ainda sem alterações de veredicto
O relógio começa a contar no primeiro dia: as alterações aparecem aqui à medida que o nosso veredicto evolui.
Fontes
- CVE Program record, CVE-2026-2525309/2026
- OpenClaw docs, gateway security (official)09/2026
- Palo Alto Networks Unit 42, OpenClaw skill marketplace supply chain research09/2026
- OpenClaw docs, overview (official)09/2026
- OpenClaw docs, model providers (official)09/2026
- OpenClaw release 2026.9.4 (official)09/2026
- OpenClaw website (official)09/2026
- OpenClaw GitHub repository, README and MIT licence (official)09/2026
Registo de verificação
Ainda não há verificações
Ainda não registámos nenhuma verificação para esta entrada. Assim que uma for executada, o seu histórico aparece aqui.
Quer isto a funcionar na sua empresa?
Testámos esta ferramenta e construímos com ferramentas assim todos os dias. Diga-nos o fluxo de trabalho e nós instalamos, integramos e entregamos a funcionar.
A conversa funciona com Gnosari, uma das ferramentas deste diretório. Uma conversa real, não um guião de vendas.