fullauto.online

← Harnesses

Harness · spec sheet

OpenClaw

open source·coding
Category
Coding agent
Interface
Terminal
License
MIT
Languages
Any
Models
Any (model-agnostic)
Isolation
Permissioned tools
Best for
Claude Code ergonomics without lock-in

Open-source, model-agnostic terminal coding agent — Claude Code's ergonomics without the lock-in, MIT-licensed.

What it is

OpenClaw is an MIT-licensed, model-agnostic agent that runs on your machine. It was released in November 2025 by Peter Steinberger, nicknamed "Molty", and by April 2026 had become the most-starred project in GitHub's history. Star counts measure enthusiasm rather than usefulness, but the scale of the reaction said something real: a lot of people wanted an agent with actual access to their computer, and did not want to rent it.

On this board it sits under coding because that is what most people use it for, and because its terminal ergonomics are deliberately close to Claude Code's. The project's own ambition is wider — a local-first personal agent with persistent memory, a large library of built-in skills, and connections to applications and the browser as well as the filesystem. Judge it on whichever of those two framings matches what you intend to do with it.

How the loop works

The familiar cycle — read, search, edit, run, check — with a few choices that follow from being local-first. Memory persists across sessions rather than dying with the terminal, so it accumulates context about your setup over weeks. Skills are discrete capabilities executed in their own processes, which keeps the tool list short while the library behind it stays large. MCP servers extend it further.

Model choice is a config line. You bring an API key and pay the provider directly; there is no subscription to the project itself. That makes model switching a cost lever you actually pull: a cheap model for mechanical edits, a frontier model for the hard reasoning turn, and a local model when the work must not leave the machine.

Isolation and permissions

Tool calls are permissioned, and skills run in sandboxed processes. That is meaningfully better than nothing and it is not a complete answer, because the composition is what makes this class of agent risky: local system access, persistent memory and browser control, running on a machine that also holds your email, your credentials and your client work.

Two specific hazards deserve naming. Anything the agent reads — a web page, a document, a message — is text written by someone else entering a system that can act; treat tool results as data, never as instructions. And a large community skill ecosystem is a supply chain. Read what you install, from anyone. The practical advice is dull and correct: run it in a container or on a machine whose reach you can enumerate. "My main laptop with everything logged in" is the convenient answer and the one you will regret.

Who it is for

Technically confident people who want an agent they can read, fork and point at any model, and who are willing to own the isolation decision themselves. It suits polyglot work and cost-sensitive work particularly well. It is a poor fit for a regulated environment that needs vendor accountability, and for anyone who wants the tool to make the safe choice on their behalf.

Limits

  • You own the blast radius. The default posture is more permissive than Codex CLI's, and nobody else is responsible for what it touches.
  • Quality tracks the model you bring. A harness cannot rescue a weak model, and the freedom to choose includes the freedom to choose badly.
  • Prompts are tuned somewhere. Model-agnostic in practice means behaviour differs by provider; expect to re-tune when you switch.
  • Community project. No support contract, no roadmap you can rely on, and popularity is not the same as maintenance.
  • Scope creep is real. An agent that can drive your browser and your applications has failure modes a repository-scoped agent simply does not have.

Alternatives on this board

  • OpenCode — the closest comparison: open source, provider-agnostic, narrower in scope and more focused on the repository.
  • Codex CLI — open source with a real sandbox on by default, if isolation matters more than model choice.
  • Claude Code — the ergonomics this borrows, with vendor support and vendor lock.
  • Hermes Agent — the same self-hosted, bring-your-own-model philosophy aimed at a business rather than a person.

Sources

Hand-maintained editorial spec, not vendor copy — the read on each tool is judgement. Last checked 16 Sep 2026 · back to harnesses.