Autonomous AI agent — 335K stars, powerful but security-challenged
OpenClaw is the fastest-growing open-source AI agent in history, hitting 335,000+ GitHub stars in just 60 days — breaking React's decade-old record. Unlike Claude Code or GitHub Copilot (which are code editors), OpenClaw is an autonomous task execution agent that operates across messaging platforms, browsers, and APIs. It supports 50+ integrations and 12 LLM providers. However, OpenClaw faces critical security challenges: 9+ CVEs discovered in its first 2 months, a malicious skill registry (20% of submissions infected), and 30,000+ exposed instances found on the open internet. Created by Austrian developer Peter Steinberger, who recently joined OpenAI.
Not a code editor — an autonomous agent that executes complex multi-step tasks across platforms, browsers, APIs, and messaging systems
Connects to Slack, Discord, email, browsers, file systems, databases, and CI/CD pipelines for end-to-end automation
Supports Claude, GPT, Gemini, Llama, Mistral, DeepSeek, and any OpenAI-compatible API including local models
Extensible via ClawHub skill registry — community-contributed automations. WARNING: 20% of submissions found to contain malicious code
OpenClaw v2026.7.1 delivers a major Control UI overhaul, native app updates, GPT-5.6 and Muse Spark 1.1 model support, and Codex coding-agent enhancements.
$0
Bring your own API keys. Security is your responsibility
Via NVIDIA
NVIDIA NemoClaw wraps OpenClaw for enterprise use
Runs as CLI, Discord bot, Slack app, or web service — operates autonomously with minimal supervision
MIT licensed, 335K+ GitHub stars, community governed. Founder Peter Steinberger recently joined OpenAI (Feb 2026)
OpenClaw has transitioned into a non-profit foundation with a dedicated team and partner ecosystem to steward open-source personal AI assistant infrastructure.
OpenClaw v2026.6.11 delivers critical reliability and stability fixes for misplaced replies, stuck message sends, gateway reconnects, and model setup failures.
CRITICAL: 9+ CVEs, malicious skill registry, 30K exposed instances. What you need to know.