BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

nanoclaw

Skill Security Solid
Works inClaude Code
Solid Reviewed

OpenClaw-style assistant functionality without OpenClaw's audit burden: security comes from OS-level container isolation rather than application-level allowl…

An AI assistant that runs Claude agents securely in their own Linux containers with filesystem isolation. Connects to WhatsApp, Telegram, Discord, or a local CLI, with memory and scheduled tasks. Built as a deliberately small, auditable alternative to OpenClaw — one process and a handful of source files instead of roughly half a million lines. The guided setup script installs Node, pnpm, and Docker if missing and pairs your first messaging channel.

30,190 starsMIT (commercial OK)FreeQuick setup

OpenClaw-style assistant functionality without OpenClaw's audit burden: security comes from OS-level container isolation rather than application-level allowlists, and the codebase is small enough to actually read before trusting it with your accounts and messages.

Security-conscious teams who need messaging platform integrations with a lightweight, container-isolated solution.

Claude Code Claude Cowork Claude Chat

https://github.com/nanocoai/nanoclaw

By qwibitai

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2 && cd nanoclaw-v2 && bash nanoclaw.sh

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

PrerequisitesDocker, Node.js, pnpm, and an Anthropic credential — the setup script (nanoclaw.sh) installs missing dependencies and walks through channel pairingCostFree

Trust Signals Reviewed

Stars30,190Contributors144Last updated2026-07-10LicenseMIT (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-07-17 · scanner vattempted-no-data

Community Pulse Active

Discussed on Hacker News, Reddit

3 mentions across 1 sources

Reviewer notes

Reviewed review. These are observations, not a security certification.

Scored from trust signals (evidence-eval-v1): 27,376 GitHub stars; contributors unknown; last commit 34d ago; license MIT.

2026-05-10: 27K stars with only 3 production mentions is a flag worth noting—this looks like a community darling that hasn't been stress-tested in real production workloads yet. The pitch is a containerized agent that bridges Anthropic's SDK to messaging platforms (WhatsApp, Telegram, Slack, etc.) with memory and scheduled jobs, which is a genuinely useful pattern for security alerting or incident notification pipelines. Tradeoff: you're trading OpenClaw's feature depth and battle-hardening for a smaller footprint, and container ops overhead is real if your team isn't already running that stack. Evaluate carefully before putting it on any path that touches sensitive comms data.

Things to check

  • Lightweight implementation may lack the feature breadth and production hardening of full OpenClaw; container-based deployment adds operational complexity for teams without containerization experience.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
4/5
Versatility
5/5
Reliability
3/5
Security
3/5
Overall score3.85 / 5.00 SolidEvaluatedMay 2026
Scored from trust signals (evidence-eval-v1): 27,376 GitHub stars; contributors unknown; last commit 34d ago; license MIT.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →