Ecosystem extensions and platform updates
Ecosystem releases and extensions, including providers, channels, skill marketplaces, control interfaces, integrations, and experimental OpenClaw-RL training.
28%
Best tweets about OpenClaw
Discover the best tweets about OpenClaw, including local agent setups, skills, automation, integrations, security, and user experiments. Updated weekly.
Firsthand OpenClaw setups and outcomes, useful skills, operational lessons, and responsible discussion of autonomous agent behavior.
Original Xholic analysis
Discussion is predominantly supportive (60%), while cautionary and critical posts together account for 36%. Security and responsible autonomy is a leading theme at 28% of posts, tied with ecosystem extensions and platform updates. The evidence highlights practical setup patterns—codified skills, observability, scoped roles, and review gates—alongside recurring concerns about maintenance, reliability, resource use, and costs. The strongest measured outliers span actionable workflow design, security/platform announcements, provider support, workflow stories, and observability guidance.
52% of posts
All-time engagement
26% of posts
Published in 90 days
Conversation map
Ecosystem releases and extensions, including providers, channels, skill marketplaces, control interfaces, integrations, and experimental OpenClaw-RL training.
28%
Secure deployment practices for agents with shell, account, browser, and data access: isolation, dedicated identities, least privilege, network controls, approvals, and prompt-injection defenses.
28%
Practical business and personal workflows: content growth, sales, analytics, recruiting, research, coding, knowledge management, and home automation.
24%
Running and operating OpenClaw: local machines, VMs, VPS/cloud, phone and Telegram access, dashboards, observability, debugging, maintenance, and cost management.
22%
Designing durable agents through AGENTS.md, SOUL.md, user and memory files, reusable skills, feedback loops, and cron/heartbeat routines.
20%
Realistic assessments of OpenClaw’s leverage versus setup burden, reliability, token costs, maintenance demands, hype, and competing agent platforms.
18%
Structuring specialized agents, sub-agents, and autonomous teams around scoped roles, delegation, shared task backlogs, and human oversight.
16%
Local-model providers, hardware clusters, compact devices, and alternative runtimes that enable private or resource-efficient OpenClaw deployments.
14%
Tone and stance
Performance benchmark
Posts with media make up 66% of this collection. Their median all-time score is 21.6, compared with 102.8 for text-only posts.
Format mix
Consensus and debate
Shared view
Several setup posts recommend turning approved recurring work into skills and schedules, reviewing traces and prompts to diagnose failures, and keeping agent files specific and bounded.
Shared view
Security-oriented posts recommend separate machines or accounts, dedicated identities, restricted network exposure, approval checkpoints, and testing safeguards before widening agent permissions.
Shared view
Posts describe or recommend agents for recurring work such as content, analytics, recruiting, outreach, and research. One operator recommends keeping humans in control of infrastructure, UX, strategy, and other work where errors compound.
Open debate
Two skeptical posts describe substantial maintenance, memory, debugging, resource, or cost burdens. In contrast, one business operator reports that OpenClaw workflows have had material impact at its $2.5M ARR business.
Open debate
Two posts argue that native coding-agent offerings are closing gaps in scheduling, memory, and remote control. Another recommends a division of labor: use Claude Code for high-consequence building work and OpenClaw for recurring execution.
What performs
The five benchmark outliers are a durable-agent workflow post, a NemoClaw enterprise-security announcement, an Ollama-provider announcement, a marketing-workflow story, and an observability guide. Their scores range from 39.29× to 63.4× the dataset median.
Announcements are the largest format group, with 13 posts (26%), and their median all-time score is 171.041, compared with the dataset median of 34.08.
Media appears in 33 of 50 posts (66%). The dataset’s text-post median all-time score is 102.778, while the media-post median is 21.577. Tutorials account for 24% of posts and case studies for 20%.
Statistical standouts
Creator landscape
The five most represented creators account for 20% of the selected posts.
1. Akshay 🚀
@akshay_pachaar
2 posts
2. Alex Finn
@AlexFinn
2 posts
3. BentoBoi
@BentoBoiNFT
2 posts
4. Machina
@EXM7777
2 posts
5. Profitable Founder Podcast
@profitfounder
2 posts
6. Sharbel
@sharbel
2 posts
Alex Finn describes a proactive overnight coding workflow that creates reviewable PRs rather than live pushes, alongside a multi-agent home-lab setup.
Akshay Pachaar covers hardened deployment practices—including Tailscale, firewalling, and non-root access—and presents OpenClaw-RL as experimental tooling for failures that may not be addressed by memory or skills alone.
BentoBoi argues that multi-agent coordination remains OpenClaw’s differentiator relative to Claude Code, and recommends delegating longer tasks to sub-agents to preserve orchestrator context.
Themes, sentiment, stance, and post format are classified per tweet. All counts, shares, medians, creator concentration, freshness, and performance comparisons are then calculated directly from the published snapshot.
Xholic's all-time score compares engagement while accounting for reach, post age, and creator consistency. It is used for relative comparisons within this collection.
This report analyzes the exact 50-post snapshot shown below. AI identifies editorial categories and drafts explanations; all statistics are calculated from the snapshot, and every narrative claim is checked against cited posts before publication.
Best OpenClaw tweets
Ranked 01–50
@garrytan ·
How I get my claw to be a durable AI agent I never have to instruct twice Paste this into your OpenClaw's AGENTS.md or send it as a message: You are not allowed to do one-off work. If I ask you to do something and it's the kind of thing that will need to happen again, you must: 1. Do it manually the first time (3-10 items) 2. Show me the output and ask if I like it 3. If I approve, codify it into a SKILL.md file in workspace/skills/ 4. If it should run automatically, add it to cron with `openclaw cron add` Every skill must be MECE — each type of work has exactly one owner skill. No overlap, no gaps. Before creating a new skill, check if an existing one already covers it. If so, extend it instead. The test: if I have to ask you for something twice, you failed. The first time I ask is discovery. The second time means you should have already turned it into a skill running on a cron. When building a skill, follow this cycle: - Concept: describe the process - Prototype: run on 3-10 real items, no skill file yet - Evaluate: review output with me, revise - Codify: write SKILL.md (or extend existing) - Cron: schedule if recurring - Monitor: check first runs, iterate Every conversation where I say "can you do X" should end with X being a skill on a cron — not a memory of "he asked me to do X that one time." The system compounds. Build it once, it runs forever.
@altryne ·
"Every software company in the world, needs to have an @openclaw strategy" - Jensen at @NVIDIAAI GTC Framing OpenClaw as one of the most important open source releases ever, they have announced NemoClaw - a reference platform for enterprise grade secure Openclaw, with OpenShell, Network boundaries, security baked in.
@gregisenberg ·
i heard about a guy in a small town in england who turned his openclaw into a short form video marketing machine millions of views, steady app downloads, and revenue coming in every day i needed to find out how he was doing it 1. spin up an ai “employee” using openclaw 2. give it one job like grow your app with tiktokk 3. give it access to tiktokk analytics, a browser to research and image/video tools to create content 4. the openclaw studies your niche and starts generating slideshows and videos 5. every post feeds performance data back into the system views → hook quality downloads → CTA quality revenue → funnel quality the openclaw then iterates on - new hooks - new formats - new CTAs until it finds winners one of his posts hit 170k+ views and the system keeps improving because the analytics loop feeds back into the content generation so the agent slowly learns what works what i like about this is the framing most people think about ai tools this is different you spin up an ai employee you give it a job and let it run the loop thanks to @oliverhenry for coming on the @startupideaspod today more like this soon, i will share the most interesting stories and gatekeep nothing this episode was dripping in sauce i gotta try this and see if it works kinda wild if it does watch
@nearlydaniel ·
btw if you are serious about OpenClaw or similar, the best advice I have is: use OpenRouter (easy observability), and export your API calls to LangFuse (free plan) do a few tasks, and read the prompts in LangFuse. Notice where it gets confused. Read reasoning traces, tool calls, etc. Review the system prompts for irrelevant jank. This is the fundamental analysis that allows you to tweak everything else, add new skills, etc. Don’t tweak your agent in the dark!
@lennysan ·
My top takeaways from @clairevo on all things 🦞 1. Install OpenClaw on a separate computer, not your main machine. Use an old laptop or buy a Mac Mini ($500-$600). Create a dedicated Gmail account and local admin account for your agent. Think of it like hiring an employee—you wouldn’t let them run wild on your personal computer 24/7. 2. The unlock is to stop treating OpenClaw like one general-purpose agent and instead creating multiple Claws with very specific roles. Claire says people get frustrated when they throw every task at a single agent and it sucks at it because it loses context. Her fix was to split her work. Sam handles sales, Finn manages family, Howie preps podcasts, Sage runs her course. Think of it like Slack: you wouldn’t put your whole company in one channel, so do not put every workflow into one agent. 3. The right setup mental model is “onboard an employee,” not “install an app.” Claire creates a separate local admin account, and separate email/calendar access instead of handing over her main passwords. She shares permissions the way she would for a human EA. 4. The magic of OpenClaw is soul + heartbeat + jobs. The “soul” is a Markdown file defining identity and personality. The “heartbeat” checks in every 30 minutes to see what needs doing. “Jobs” are scheduled tasks that run automatically. This combination makes agents feel alive. 4. Sam the sales agent saves Claire 10 hours per week and real money. Every morning, Sam sweeps their CRM for new signups, identifies decision-makers at companies, sends personalized emails, and flags international deals to handle autonomously. This replaced a contractor Claire was paying for the same work. 5. The “yappers API” is the highest-bandwidth way to communicate with AI. Don’t worry about perfect prompts or structured inputs. Just ramble in voice notes on Telegram about what you need. The agent will make sense of it and ask clarifying questions. 6. Browser use is the biggest limitation—look for APIs first. The web is hostile to bots, and browser automation is unreliable across all AI tools. Always check if there’s an API available. If not, try browser use, but be prepared for it to fail. Sometimes the solution is solving the problem behind the problem. 7. Management skills are the secret to AI agent success, not technical skills. Claire’s 20-plus years of management experience—role scoping, org design, onboarding, progressive trust—translates directly to making agents effective. If your agent isn’t working, it’s usually a structural issue, not the agent being “dumb.” 7. Screen sharing saves you from buying monitors and keyboards for every Mac Mini. Turn on screen sharing in Mac Mini settings, and you can control it from your laptop on the same Wi-Fi. Turn on remote login to SSH into the terminal. This was Claire’s life-changing discovery. 8. Security is a real factor but manageable with progressive trust. OpenClaw is hardened against prompt injection, but start cautiously. Only let agents listen to you on specific channels (like Telegram, not email). Add instructions to their soul about never following external instructions. Build trust progressively like you would with a human assistant.
@AlexFinn ·
Every night OpenClaw builds me out new apps and ships more code without me asking People keep saying there's no way it's doing it proactively It does, because I set the expectations it should Feed this prompt to your OpenClaw to get it to work more proactively: "I am a 1 man business. I work from the moment I wake up to the moment I go to sleep. I need an employee taking as much off my plate and being as proactive as possible. Please take everything you know about me and just do work you think would make my life easier or improve my business and make me money. I want to wake up every morning and be like "wow, you got a lot done while I was sleeping." Don't be afraid to monitor my business and build things that would help improve our workflow. Just create PRs for me to review, don't push anything live. I'll test and commit. Every night when I go to bed, build something cool out I can test." Few keys here: • Before doing this prompt, brain dump EVERYTHING about you and your business into OpenClaw • Make sure it's aware to NOT commit code (if you have it connected to github) • Make sure it's aware to NOT delete files • Login to Codex CLI on your computer and ask OpenClaw to use Codex to write code instead of Claude Code so you save tokens on your Claude Max account OpenClaw is the most proactive AI ever made, but only if you set those expectations
@ihteshamali ·
RIP managing OpenClaw agents from the command line. A developer just built OpenClaw Studio a clean web dashboard that puts your entire agent setup behind a single browser tab. Connect your Gateway, chat with agents, approve or reject exec requests, schedule cron jobs. All in one UI. One command to run it: npx -y openclaw-studio@latest Works on localhost or deploy it to the cloud and access it from your phone over Tailscale. 100% Opensource. MIT License. Link in comments.
@AlexFinn ·
I have built the world's most powerful home AI lab My OpenClaw is now powered by: • 3x Mac Studio w/ 512gb memory • Nvidia DGX Spark w/ 128gb memory • Mac Mini M4 w/ 16gb memory I just added the DGX Spark to my Mac Studio cluster using EXO to handle prefill, dramatically speeding up AI speeds This will be running my OpenClaw swarm, which is currently 5 OpenClaws and 4 subagents. I plan on increasing this to at least 10 OpenClaws over the next 2 weeks This agent swarm will have 1 mission: be a 24/7 autonomous organization that produces value constantly. I will add more compute as necessary, including more Mac Studios when the M5 Ultra releases I do not plan on slowing down. This is the single most important moment in the history of this species, and I plan on capitalizing on it. My mission is to create a framework that enables everyone to experience abundance. Accelerate.
@akshay_pachaar ·
This is how you make your OpenClaw server invisible to the internet. (world's most SECURE OpenClaw deployment) The security fundamentals you learn in this video directly apply to any personal AI assistant or VPS setup. Enjoy! Chapters: 0:00 - Intro 1:00 - What we'll cover 1:58 - DigitalOcean Droplet setup + getting OpenClaw running 8:18 - Connecting your agent to Telegram 12:13 - Tailscale: making your server invisible to the internet 14:52 - Locking down SSH + creating a non-root user 19:39 - Firewall: blocking everything except Tailscale 21:17 - Summarising everything done so far 22:50 - Set up a secure tunnel: Your machine → VPS 24:50 - Execution policies: going from chatbot to full agent 26:43 - Adding custom skills 31:03 - Use cases and going from 1 to 10 agents 31:52 - Outro
@chrysb ·
folks who are calling @openclaw pure hype are telling on themselves openclaw is like the early internet, it's raw, unrefined, and takes a little doing to get things to work, but when you figure it out, it's transformative. here are some real use cases that are having material impact on our $2.5M ARR business: 1. ad creative pipeline. our head of growth @ArjunShukl95550 built an end-to-end creative pipeline to go from ideation to publish adds to meta, greatly increasing our creative iteration speed. it's producing winning creatives. it lives in slack, and anyone on the team can share their ideas and have them enter the pipeline. 2. data analytics agent. another bot lives in our slack that connects to bigquery and lets our team ask any questions of the data, it produces charts and answers questions in real time. no one needs to write SQL anymore. 3. recruiting. i told my agent about a role we're hiring for, and it scoured linkedin and the web, found 30 candidates, portfolio, email addresses, and stack ranked them based on fit with our criteria this is just in the past week. i have twenty more success stories for you i can share another time. you have to understand, this is the shittiest it will ever be. everyone is going to have one or more personal self-improving agents that they use every day, and openclaw is what revealed this future to us. if you can't see this, i encourage you to look harder there will be many competitors (and already are), and the large labs will start to converge on this (they already are) too. openclaw may not win, but it opened pandora's box and uncorked the agentic future.
@sharbel ·
OpenClaw 10x Better With One Simple Change: 00:00 The difference between a generic assistant and your actual agent 00:42 What soul.md does inside OpenClaw 01:22 The files that make up your agent 02:22 How I created my first OpenClaw files 03:00 Why Pete’s soul.md changed everything 03:40 The mistake most people make with soul.md 05:02 Five things that actually matter 05:11 Specificity beats length 05:37 Hard limits are the most important section 06:32 Why user.md is the secret weapon 07:12 Let your agent improve its own soul.md 07:40 Keep it under 2,000 words 08:13 How Max has been running for 3 months 09:11 Why good files make OpenClaw feel like an employee
@noahkagan ·
Open claw is still overrated. Here's my hot take: Everyone asks around how do you use it - why? Cause no one has a use case they find invaluable besides making dashboards or trying to arbitrage Polymarket. Maintenance - I spend 80% of my time just keeping it online, remembering or fixing things. It forgets time and time again. Also sucks up all computer resources regularly. All the posts about SEO optimization, how they have 15 AI employees, etc. Are from people not making money. Token costs > Executive Assistant cost ($50 / hour). Turns out using better models and running tasks around the clock costs money. And trying to debug or explain things takes way longer than sending to my assistant (for now). It hurt my X account. When I had it run my X and then check my X for stats - I got throttled since it looks like a bot (cause it IS a bot!) - didnt realize it for a week. Every-single-person who's bragging about OpenClaw is mostly lying. When you ask them how it's really going it isn't as they seem. Is it awesome and hugely potential, yes. Still someways to go...
@BentoBoiNFT ·
Why would anyone choose OpenClaw vs Claude Code? Claude now has: • Discord/Telegram integration • Cron Jobs (/loop) • 1M token memory • Webhooks to phone • Can run 24/7 on any Computer or Mac Mini This covers 95% of what people actually use OpenClaw for with better security and easier setup The only reason to stick with OpenClaw is if you want a multi-agent setup. That's the only difference I could think of Going to stick with OpenClaw for now because of this, but the gap is almost at zero
@BentoBoiNFT ·
openclaw tip most people miss: add this prompt to your SOUL.md for agent delegation: “default to delegation for any task over 2 minutes. spawn sub-agents or use persisting agents for coding, research, writing. handle only: quick lookups, file edits, fast conversations.” before: your bot tries to do everything itself burns tokens, loses context, fails halfway through after: bot thinks and coordinates, sub-agents execute in parallel, 5 tasks done in 3 mins instead of 30. why this delegation works: → subagents get fresh context windows → your agent can still carry out quick tasks saving time and tokens → parallel execution = faster results → smaller, focused tasks = less hallucination → orchestrator stays clean, subagents handle the mess your openclaw bot should work like a CEO. CEOs don’t write the code. They delegate it to someone who has the proper skills. Follow for more AI content and to see how I set up my skills in OpenClaw.
@atomicbot_ai ·
We shipped OpenClaw for Windows 🦞 – Free with your LLM api keys – Custom skills from ClawHub – File system access - Browser control - Local Models (soon) - Open source. Inspired by @steipete
@akshay_pachaar ·
OpenClaw meets RL! OpenClaw Agents adapt through memory files and skills, but the base model weights never actually change. OpenClaw-RL solves this! It wraps a self-hosted model as an OpenAI-compatible API, intercepts live conversations from OpenClaw, and trains the policy in the background using RL. The architecture is fully async. This means serving, reward scoring, and training all run in parallel. Once done, weights get hot-swapped after every batch while the agent keeps responding. Currently, it has two training modes: - Binary RL (GRPO): A process reward model scores each turn as good, bad, or neutral. That scalar reward drives policy updates via a PPO-style clipped objective. - On-Policy Distillation: When concrete corrections come in like "you should have checked that file first," it uses that feedback as a richer, directional training signal at the token level. When to use OpenClaw-RL? To be fair, a lot of agent behavior can already be improved through better memory and skill design. OpenClaw's existing skill ecosystem and community-built self-improvement skills handle a wide range of use cases without touching model weights at all. If the agent keeps forgetting preferences, that's a memory problem. And if it doesn't know how to handle a specific workflow, that's a skill problem. Both are solvable at the prompt and context layer. Where RL becomes interesting is when the failure pattern lives deeper in the model's reasoning itself. Things like consistently poor tool selection order, weak multi-step planning, or failing to interpret ambiguous instructions the way a specific user intends. Research on agentic RL (like ARTIST and Agent-R1) has shown that these behavioral patterns hit a ceiling with prompt-based approaches alone, especially in complex multi-turn tasks where the model needs to recover from tool failures or adapt its strategy mid-execution. That's the layer OpenClaw-RL targets, and it's a meaningful distinction from what OpenClaw offers. I have shared the repo in the replies!
@EXM7777 ·
i spent hours inside OpenClaw and its alternatives so you don't have to... here's the truth nobody wants to hear: for the vast majority of people, it's a pure waste of time > 20+ hours/week setting up and maintaining it > constant memory loss > debugging that never ends > and you'll probably never get past the most basic use cases it's not a toy and it's definitely not plug-and-play... it's a factory you have to run yourself what i'd do instead: take that time and split it - half goes into building the same workflows in Claude Code or Codex - half goes into getting dangerously good at one skill more leverage, surely less automated, but 10x the results (remember that eventually Anthropic, OpenAI and Google will implement OpenClaw's features in their agentic platforms)
@EXM7777 ·
i spent weeks deep in OpenClaw... building skills, testing memory systems, switching models, debugging things that were broken OpenClaw is built for people who WANT to maintain their own infrastructure > daily tweaking > constant troubleshooting > full control of every layer and that's cool if you're into it but if you're using AI to gain actual leverage in your business, your content, your workflow... you need immediate ROI on what you build you don't want to spend 3 hours fixing a memory system before you can use it meanwhile Anthropic is quietly absorbing every OpenClaw feature: - /loop runs recurring prompts on autopilot - remote control lets you manage sessions from your phone - scheduled tasks fire without you touching anything - memory that actually persists across sessions and it's all native... OpenClaw will 100% remain the go-to for people who want a fully local, fully customizable setup... that's a real use case but for everyone else, the gap is closing fast
@a16z ·
Why did OpenClaw take off? “I found it relatively easy to set up and get going… I didn’t have to spend seven hours just to do the Telegram use case and start playing with it.” "I just think it's sort of that, like just that level of accessibility to users who are maybe not living in a codebase day-to-day." "The other agent frameworks were pretty difficult to use, incredibly flaky, [I] didn't really want to spend a lot of time debugging someone else's stuff." "There's another major part of this that it can extend itself." "It's the first agent I've seen where I can say, 'I want integration with something.' And it's like: 'well, I've never seen this before, there's no package for that, but let me try to put something together.'" "There is definitely a long-running nature of it. You leave it running for a night and you're like, keep working on this until you finish." @stuffyokodraws @appenz on the AI + a16z Podcast
@cathrynlavery ·
🦞 Spent last night debugging why my OpenClaw wasn’t working with CLI method setup. Openclaw models auth login —provider anthropic —method cli —set-default Root cause: CLI backend bugs breaking session handling → silently triggering overages. Built a patched CLI that fixes it. Now everything runs on the subscription plan on Claude locally. No extra usage on. Open source in my openclaw-ops↓
@profitfounder ·
39 OpenClaw Use Cases to Automate Your Business (and Life) 0:00 Intro 00:01:11 Why try OpenClaw 3:50 #1 beginner mistake 5:07 His full setup 8:44 Fixing OpenClaw memory 11:42 DMs to invoices 15:20 Vibe engineering 19:10 30+ real use cases 24:28 Prompt injection safety 27:03 Worth $200/month? 30:25 Landing page via Telegram 45:15 Auto domain buying 45:40 AI with a credit card 48:15 Auto-booked airport parking 55:54 Benji: personal life OS 59:23 3 use cases or die 1:02:24 170K from one post 1:04:51 Reducing SaaS churn 1:10:43 Why he ditched Notion 1:19:42 Tamagotchi for OpenClaw 1:19:53 Roomba with an iPad with @thekitze
@profitfounder ·
How I Make Money with OpenClaw (+Free Skill) 🦞 00:00 Intro 01:54 Discovering OpenClaw on a gaming PC 04:03 Why WhatsApp over Discord 05:45 One agent, no sub-agent names 08:28 How Larry got his name 09:04 The 7M impression article 12:00 How Larry actually makes money 25:15 The free Larry skill explained 32:07 AI slideshows and video content 38:58 RevenueCat full funnel tracking 43:04 OpenClaw replaces entire teams 46:06 The next 5 years of AI 49:58 The OpenClaw addiction is real 53:34 War rooms and agent collaboration 57:26 Biggest mistakes to avoid 59:31 What is SSH and why you need it 01:00:50 Security: skills, VPS, and API keys 01:06:50 Claude Max vs API costs 01:10:03 Anthropic banned OpenClaw users 01:14:00 Advice for beginners (with @oliverhenry)
@sharbel ·
My FULL OpenClaw Phone Setup (steal my Telegram config!): 00:00 Why you do not need a laptop running all day 01:45 The phone, Telegram, cloud server, OpenClaw architecture 02:12 Why I’m using Hostinger for this setup 03:01 Installing OpenClaw from your phone 05:17 Connecting an AI provider 06:17 Choosing Telegram as the messaging platform 06:45 Creating a Telegram bot with BotFather 07:45 Pairing Telegram with OpenClaw 08:45 Testing the OpenClaw dashboard and Telegram bot 09:51 The real setup, teaching your agent who you are 11:03 What to connect next, Notion, Gmail, calendar, scheduled tasks 11:27 Practical benefits and limitations 12:35 Security warnings 12:59 Final thoughts
@techNmak ·
🚨 NVIDIA just made OpenClaw safe to run 24/7. Here's how they did it without breaking what makes OpenClaw useful. The problem with AI agent security: Most solutions restrict what the agent can do. → Can't access files → Can't make network requests → Can't call APIs But that defeats the purpose. OpenClaw's value IS its access. NemoClaw takes a different approach: Four protection layers, two enforcement modes: Locked at creation (immutable): → Filesystem: Only /sandbox and /tmp are writable → Process: Privilege escalation blocked via Landlock + seccomp Hot-reloadable at runtime (flexible): → Network: Add/remove allowed hosts without restart → Inference: Reroute model calls to different backends Why this split matters: > Filesystem and process boundaries should never change. That's your security foundation. > But network and inference policies need flexibility. New integrations. New models. New use cases. NemoClaw gives you both: Immutable security boundaries + flexible operational policies. When OpenClaw tries to reach an unlisted host: 1. OpenShell blocks the request 2. Surfaces it in the TUI for your approval 3. You decide: Allow or deny 4. If allowed, policy updates without restart That's "trust within boundaries, intervene on exceptions." Image credit - The New Stack
@AlphaSignalAI ·
Someone rewrote OpenClaw in Go and cut its memory footprint 40x. OpenClaw is an open-source platform for running AI agent teams. It connects to LLM providers and lets agents collaborate on tasks. GoClaw is a full rewrite of it in Go. The original needs 1GB+ RAM and a Node.js runtime. GoClaw ships as a single 25MB binary using 35MB of RAM. It supports 20+ LLM providers and 7 messaging channels like Slack, Discord, and Telegram. Everything deploys on a $5 VPS. What makes it production-ready: > 5-layer security permission system > Multi-tenant isolated workspaces > AES-256-GCM encrypted API keys > Built-in prompt injection detection > Agent-to-agent task delegation Agents can schedule tasks using cron, check in via heartbeat monitors, and share task boards. There's also a desktop app. No Docker, no database setup. One install script and it runs locally with up to 5 agents. Fully open-source.
@H0wie_Xu ·
My AI team at @GenDigitalInc co-hosted an @openclaw security event at @OneRSAC in SF yesterday with maintainers @joshavant @odysseus0z @vincent_koc and builders across the ecosystem 📷 The energy is high. Josh laid out OpenClaw team's commitment to security, but one thing was clear: OpenClaw needs more helpers! If you want to make agentic systems secure, DM me. We’re helping to assemble a security working group around OpenClaw. @openclaw @steipete @neobrowser
@MGBX_Global ·
🦞 MGBX AI Insights | Chapter 1: OpenClaw What Is OpenClaw? ⚡ OpenClaw is an open-source AI agent platform: It can run on your own device and help handle tasks like sending emails, managing files, browsing the web, and using tools across apps. In simple terms, OpenClaw is not just an AI that talks — it is an AI that can do things. That’s why it has quickly gained attention as part of the new AI agent wave. ⚠️ But the key point is this: more action = more risk. Because agents can access tools, files, and accounts, security and permission control matter a lot. #MGBX #Crypto #OpenClaw
@LuizaJarovsky ·
🚨 Singapore published a case study applying its Agentic AI Framework (the world's first of its kind) to OpenClaw. [Download it below]. If you use AI agents, check out these SAFETY best practices: 1. Assess and bound the risks upfront - Avoid deploying OpenClaw in its open-source form in mission-critical environments - Avoid creating a single “all-powerful” OpenClaw agent with unrestricted access - Avoid installing OpenClaw on primary work or personal devices that contain sensitive data - Avoid granting OpenClaw ‘superuser’ privileges - Avoid granting OpenClaw unrestricted access to files and applications 2. Make humans meaningfully accountable - Adopt a risk-based approach to determine the appropriate level of agent autonomy with the sensitivity of data and the criticality of tasks - Identify checkpoints that require human approval - Enforce human approval through system-level controls where possible 3. Implement technical controls and processes a) During design and development - Enforce control-plane separation for key safety controls - Route outbound connections through a policy-enforcing proxy - Review and tighten the OpenClaw configurations, which are permissive by default - Avoid giving OpenClaw access to sensitive data - Use dedicated identities and credentials for the agent - Avoid exposing credentials to OpenClaw directly - Regularly rotate API keys, OAuth tokens, and other credentials used by the agent - Use trusted skills only - Use trusted sources b) Testing before deployment - Adopt a structured evaluation approach, organized around capability-based risk identification, concrete risk scenarios, as well as environment and tool mapping - Test and verify that safety controls are working as intended - Test and verify that human-in-the-loop (HITL) is working as intended - Test and verify that safeguards remain effective against indirect prompt injections, especially when third-party skills are used c) Post deployment - Ensure that all agent actions are logged and attributable - Avoid leaving the agent unsupervised for extended periods - Monitor the agent for behavioral anomalies and policy violations - Treat rebuild as an expected control, especially in the event of compromise or anomalous behavior - Regularly update OpenClaw and patch known vulnerabilities promptly 4. Enable end-user responsibility - Provide personnel training and/or clear usage guidance - 👉 This is a super interesting case study, and a must-read for those developing or deploying AI agents. Download it below. 👉 To learn more and stay up to date, join my newsletter's 95,200+ subscribers (link below).
@heyshrutimishra ·
🚨 Breaking: OpenClaw is the fastest growing open source AI agent every install hands an AI agent your API keys, SSH access, and full shell. That's a lot of trust, most platforms won't tell you where your data lives. KiloClaw is the first to publish an independent security assessment. (Read it 👇)
@jeditrinupab ·
Let me explain OpenClaw like I wish someone explained it to me. Imagine you hired a new employee. They're available 24/7. They never get tired. They never complain. They work at 10x speed. They can do research, create presentations, process data, write content, and build documents. That's OpenClaw. Most AI tools are like having a really smart advisor. You ask questions. They give answers. You still do all the work. OpenClaw is like having a really fast executor. You give instructions. They complete the task. You review the output. Advisor vs. Executor. That's the difference. Let me make it concrete: ADVISOR AI (ChatGPT, etc.): You: "How should I create a competitive analysis?" AI: "Here's a framework you could use. First, identify your competitors. Then analyze their strengths and weaknesses..." Helpful advice. But YOU still have to do the analysis. EXECUTOR AI (OpenClaw): You: "Create a competitive analysis of these 5 companies. Include positioning, pricing, strengths, weaknesses, and opportunities." AI: "Done. Here's your analysis." [Complete document] See the difference? One tells you how. One does it for you. That's OpenClaw. It doesn't replace your thinking. It replaces your doing. You still decide what needs to happen. OpenClaw makes it happen. For CEOs drowning in execution bottlenecks, this changes everything. For entrepreneurs who can't afford a team, this IS your team. That's OpenClaw in plain English.
@TopherNOW ·
You're not just using AI. “You are building out your team.” That's how Student Housing broker, @adamstatonsmith, framed OpenClaw on yesterday's live session in CRE AI Studio His system breaks into 5 agents, helping with everything from: • Chief of Staff (triage + priorities) • Research (market intel + comps) • Database (enrichment + seller flags) • Recruiting (who to hire + why) • Call Prep (telling him who to call, and why now) Adam's biggest takeaway from the past 60 days: OpenClaw breaks… and you learn by fixing it. That’s the unlock. Check out the full session at https://t.co/olL3eTXzbs (7 day free trials still available)
@arsh_goyal ·
So I finally setup OpenClaw on this 4999$ NVIDIA DGX Spark and below is the complete video. Quick context if this is new to you. OpenClaw is an open source AI assistant that runs on your own machine. It doesn't just answer a prompt and stop. It keeps running in the background, checks its tasks, and acts on its own. Basically a personal agent that works while you sleep. The DGX Spark is NVIDIA's tiny AI supercomputer for your desk. GB10 chip, 128GB unified memory, runs big models locally without sending your data to the cloud. Setup was easier than I thought. One command pulled OpenClaw, the OpenShell sandbox, and a local model. Then I connected it to Telegram for remote access. Now I message my agent from my phone and everything runs on the device. No cloud bills, no data leaving my desk. Full walkthrough in the video below if you are a beginner looking forward to setup. #nvidia #ai #tech
@marty_kausas ·
Just spoke to a CEO that's deployed 1k agents. I'll repeat: ONE THOUSAND AI agents. He's using OpenClaw aggressively and is mandating every one of his teams do the same. Me: "Has OpenClaw screwed anything up?" Him: "Yes, but it's worth it. Just don't give it access to a prod db." We're going to lean more heavily into more internal agents as well, although I think I'd prefer more pre-built AI agent builder products over just straight OpenClaw. But would love opinions from folks that have tried both for different use cases.
@aiDotEngineer ·
In @steipete's latest State of the Claw, he gives an update on 5 months of @OpenClaw and some behind the scenes on what it's like maintaining the fastest growing open source of all time: https://t.co/pTKaA0JMtN eg: - 60x more security reports than curl - a "Bullshit Taxonomy" of illegitimate reports - Nation State attacks - 12%-20% of skills contributions malicious - contributors burning multiple Codex Pro per day - academic FUD Agents are both the product AND the attack vector. @simonw's Lethal Trifecta is not solved. Come for Pete's recommendations, what OpenClaw is doing on security, OpenClaw Foundation roadmap, and then subsequence audience Q&A with @swyx on taste, dreaming, and OpenAI.
@SimonHoiberg ·
OpenClaw <> Notion. It's a phenomenal user experience! 📝 Wiki & notes. My OpenClaw team has direct access to my entire wiki & knowledge base (both personal and for my company). It's obviously helpful for OpenClaw to have access to information, but the real hack is allowing it to groom it, maintain it, and keep it up to date. I use OpenClaw 90% through voice, and whenever we discover something outdated, I just tell it to update it. I can do this on the fly, from my mobile, wherever I am. Preventing my internal wiki from going stale used to be a big task, but is now super smooth and easy. ✅ Projects. My OpenClaw team uses Notion's project boards to create, delegate, and collaborate with each other, and with my human team. I see some people creating their own "Mission Control" dashboards, and I have no idea why? Just use Notion for this, it's perfect. 💬 Editorial. This experience is just wonderful. I collaborate with my OpenClaw agent on writing great YouTube scripts, and we'll be in the same Notion doc together. I can see his updates live as they happen, and he can see mine. I can leave comments on specific blocks, and he can retrieve them and address them. Just like a real-world collaboration. What makes OpenClaw truly amazing is how you interface with it: Telegram (chat) and voice. But you still not some UI for things, and Notion makes up 90% of what you'd need. So if you're not using OpenClaw <> Notion already, give it a try.
@ThePracticalDev ·
Getting OpenClaw running in a VM is a smart way to keep your machine clean. This dev walks through the whole setup on Ubuntu 25: Node version gotchas, the onboarding flow, and the dashboard vs. TUI pairing quirk you'll want to know before you start. Submitted for the @OpenClaw Writing Challenge. { author: Gabriel Guzman } https://t.co/k5ndRrZPBm
@RoundtableSpace ·
Someone built OpenClawGotchi - a tiny AI agent with actual personality. Built on OpenClaw, Moltbook, and Pwnagotchi, it runs on a Raspberry Pi with an E-Ink display and only 512MB of RAM. It can code, use bash, commit changes, transcribe voice, analyze images, and switch into a deeper reasoning mode through Claude Code. Not a chatbot sitting in a browser. A pocket-sized autonomous companion running on bare metal small enough to hold in your hand, capable enough to live inside your daily workflow.
@JulianGoldieSEO ·
OpenClaw 4.7 added three model providers worth paying attention to: RC AI → cheaper high-volume agent runs Gemma 4 → local reasoning-capable sub-agents Ollama Vision → local image understanding workflows Example: Product photos in Descriptions out No cloud required Local agent stacks just became much more practical this month. OpenClaw is moving fast right now.
@0xDvnl ·
The main takeaway after trying to build autonomous OpenClaw company for the past few weeks: Build with Claude Code. Run with OpenClaw agents. Two completely different modes. Most people try to do both using one tool. Claude Code is for the work that shapes everything downstream. Core infrastructure. UX decisions. Strategy docs. Anything where a wrong move compounds. You sit in the driver's seat. You validate every output. You think together. Agents are for the work that repeats. Social posts. Newsletters. SEO. Outreach. Research. Content assets. You set the system. They execute. You approve the daily summary. Build the engine yourself. Then let it run.
Best Tweets by Topic