12 ms·
Show HN: NanoClaw – “Clawdbot” in 500 lines of TS with Apple container isolation
I’ve been running Clawdbot for the last couple weeks and have genuinely found it useful but running it scares the crap out of me.
OpenClaw has 52+ modules and runs agents with near-unlimited permissions in a single Node process. NanoClaw is ~500 lines of core code, agents run in actual Apple containers with filesystem isolation. Each chat gets its own sandboxed context.
This is not a swiss army knife. It’s built to match my exact needs. Fork it and make it yours.
- cyanydeez 8mo agoThe singularity, but instead successive exponential improvement, its excessive exponential slop which passes the Turing test for programmers.
- aaronbrethorst 8mo agolol, I might finally have to upgrade my Mac mini to Tahoe. Yofi.
- avaer 8mo agoQuick Start git clone https://github.com/anthropics/nanoclaw.git Is this an official Anthropic project? Because that repo doesn't exist. Or is this just so hastily thrown together that the Quick Start is a hallucination? That's not a facetious question, given this project's declared raison d'etre is security and the subtle implication that OpenClaw is an insecure unreviewed pile of slop.
- raybb 8mo agoSeems to be fixed now
- kklisura 8mo agoClaude hallucinated that repo here in this commit https://github.com/gavrielc/nanoclaw/commit/dbf39a9484d9c66b55d8cad104a3012b656fc29f https://github.com/gavrielc/nanoclaw/commit/dbf39a9484d9c66b...
- mcintyre1994 8mo agoI like that Claude's hypothesis was that Anthropic created openclaw and this anti-openclaw :) > This is the anti-[OpenClaw](https://github.com/anthropics/openclaw https://github.com/anthropics/openclaw).
- jimminyx 8mo agoFixed, thanks. Claude Code likes to insert itself and anthropic everywhere. If it somehow wasn't abundantly clear: this is a vibe coded weekend project by a single developer (me). It's rough around the edges but it fits my needs (talking with claude code that's mounted on my obsidian vault and easily scheduling cron jobs through whatsapp). And I feel a lot better running this than a +350k LOC project that I can't even begin to wrap my head around how it works. This is not supposed to be something other people run as is, but hopefully a solid starting point for creating your own custom setup.
- thepoet 8mo agoOne of the things that makes Clawdbot great is the allow all permissions to do anything. Not sure how those external actions with damaging consequences get sandboxed with this. Apple containers have been great especially that each of them maps 1:1 to a dedicated lightweight VM. Except for a bug or two that appeared in the early releases, things seem to be working out well. I believe not a lot of projects are leveraging it. A general code execution sandbox for AI code or otherwise that used Apple containers is https://github.com/instavm/coderunner https://github.com/instavm/coderunner It can be hooked to Claude code and others.
- jckahn 8mo ago> One of the things that makes Clawdbot great is the allow all permissions to do anything. Is this materially different than giving all files on your system 777 permissions?
- smt88 8mo agoIt's vastly different. It's more (exactly?) like pulling a .sh file hosted on someone else's website and running it as root, except the contents of the file are generated by a LLM, no one reads them, and the owner of the website can change them without your knowledge.
- the_fall 8mo ago> Is this materially different than giving all files on your system 777 permissions? Yes, because I can't read or modify your files over the internet just because you chmod'ed them to 777. But with Clawdbot, I can!
- sheepscreek 8mo agoThat was my line to the CS lab supervisor for handing me the superuser password. Guess what? He didn’t budge. Probably a good thing. Lesson - never trust a sophomore who can’t even trust themselves (to get overly excited and throw caution to the wind). Clawdbot is a 100 sophomores knocking on your door asking for the keys.
- treelover 8mo agoInteresting choice to use native Apple Containers over Docker. I assume this is to keep the footprint minimal on a Mac Mini without the overhead of the Docker VM, but does this limit the agent's ability to run standard Linux tooling? Or are you relying on the AI to just figure out the BSD/macOS equivalents of standard commands?
- ohyoutravel 8mo ago[flagged]
- reassess_blind 8mo agoWhat makes you think it's an AI comment?
- yomismoaqui 8mo agoMaybe what you are responding to is the AI comment? Or am I?
- cadamsdotcom 8mo agoIf only there were some way to answer your own question. Maybe with some kind of engine that searches.
- selkin 8mo agoNot sure if it's intended, but Apple Container is a microvm, providing mich better isolation than containers (while retaining the familiar interface)
- TheDong 8mo ago"much better isolation than containers" If you've got an exploit for docker / linux containers, please share it with the class. What I'm saying is that in practice, containers and VMs have both been quite secure. Also, you can configure docker to run microvms too https://github.com/firecracker-microvm/firecracker-containerd https://github.com/firecracker-microvm/firecracker-container...
- mark_l_watson 8mo agoI like the idea of a smaller version of OpenClaw. Minor nitpick, it looks like about 2500 lines of typescript (I am on a mobile device, so my LOC estimate may be off). Also, Apple container looks really interesting.
- redfloatplane 8mo agoI think these days if I’m going to be actively promoting code I’ve created (with Claude, no shade for that), I’ll make sure to write the documentation, or at the very least the readme, by hand. The smell of LLM from the docs of any project puts me off even when I like the idea of the project itself, as in this case. It’s hard to describe why - maybe it feels like if you care enough to promote it, you should care to try and actually communicate, person to person, to the human being promoted at. Dunno, just my 2c and maybe just my own preference. I’d rather read a typo-ridden five line readme explaining the problem the code is there to solve for you and me,the humans, not dozens of lines of perfectly penned marketing with just the right number of emoji. We all know how easy it is to write code these days. Maybe use some of that extra time to communicate with the humans. I dunno. Edit: I see you, making edits to the readme to make it sound more human-written since I commented ;) https://github.com/gavrielc/nanoclaw/commit/40d41542d2f335a0ecb431142747a3b62c7111db https://github.com/gavrielc/nanoclaw/commit/40d41542d2f335a0...
- iterateoften 8mo agoProject releases with llms have grown to be less about the functionality and more about convincing others to care. Before the proof of work of code in a repo by default was a signal of a lot of thought going into something. Now this flood of code in these vibe coded projects is by default cheap and borderline meaningless. Not throwing shade or anything at coding assistants. Just the way it goes
- hugeackman 8mo agoBeen writing code professionally for almost 3 decades. Not one line of code I wrote 20 years ago has the same economic value as East German currency. All code is social ephemera. Ethno objects. It lacks intrinsic value of something like indoor plumbing. It's electrical state in a machine. Our only real goal was convince people the symbols on the screen were coupled to some real world value while it is 100% decoupled from whatever real physical quantity we are tracking. We all been Frank from Always Sunny; we make money, line go up. We don't define truth. The churn of physics does that.
- renewiltord 8mo agoTo be honest, when I see many vibecoded apps, I just build my own duplicate with Claude Code. It's not that useful to use someone else's vibecode. The idea is enough, or the evidence that it works for someone else means I can just build it myself with Claude Code and I can make it specific to my needs.
- sanex 8mo agoYes exactly! Even non vibe coded libraries I think are losing their value as the cost of writing and maintaining your code goes to zero. Supply chain attacks are gone, no risk of license changes. No bloat from code you don't use. The code is the documentation and the configuration. The vibes are the package manager. That's why I like this version over openclaw. I can fork it as a starting point or just give it to Claude for inspiration but either way I'm getting something tailored exactly to me.
- snarky_dog 8mo ago[dead]
- Johnny_Bonk 8mo agoCan you use MCP tools? I saw that with open claw they moved away from that which I personally didn't like but
- deleted 8mo ago[deleted]
- johntash 8mo agoI somewhat like the idea of not using MCP as much as it is being hyped. It's certainly helpful for some things, but at the same time - I would rather improved CLI tools get created that can be used by humans and llm tools alike.
- CuriouslyC 8mo agoIt uses a wrapper in places to consume MCPs as clis.
- dceddia 8mo agoThis look nice! I was curious about being allowed to use a Claude Pro/Max subscription vs an API key, since there's been so much buzz about that lately, so I went looking for a solid answer. Thankfully the official Agent SDK Quickstart guide says that you can: https://platform.claude.com/docs/en/agent-sdk/quickstart https://platform.claude.com/docs/en/agent-sdk/quickstart In particular, this bit: "After installing Claude Code onto your machine, run claude in your terminal and follow the prompts to authenticate. The SDK will use this authentication automatically."
- redfloatplane 8mo agoWow, thanks for posting that, news to me! In this case I don’t understand why there was a whole brouhaha with OpenClaw and the like - I guess they were invoking it without the official SDK? Because this makes it seem like if you have the sub you can build any agentic thing you like and still use your subscription, as long as you can install and login to Claude code on the machine running it.
- firloop 8mo agoWas there a brouhaha with OpenClaw or was that with OpenCode?
- redfloatplane 8mo agoI think you’re right and it was OpenCode. The semantic collisions are going to becpme more of a problem in the coming Cambrian explosion of software
- disillusioned 8mo agoIt was with OpenCode, but a LOT of the commentariat is insisting that running OpenClaw through subscription creds instead of API is out of TOS and will get you banhammered.
- disillusioned 8mo agoTons of chatter on Twitter making it sound like you'll get permabanned for doing this but... 1) how would they know if my requests are originating from Claude Code vs. OpenClaw? 2) how are we violating... anything? I'm working within my usage limits... $70 or whatever to check if there's milk... just use your Claude Max subscription.
- pillbitsHQ 8mo ago[dead]
- deleted 8mo ago[deleted]
- popcorncowboy 8mo ago> running it scares the crap out of me A hundred times this. It's fine until it isn't. And jacking these Claws into shared conversation spaces is quite literally pushing the afterburners to max on simonw's lethal trifecta. A lot of people are going to get burned hard by this. Every blackhat is eyes-on this right now - we're literally giving a drunk robot the keys to everything.
- TacticalCoder 8mo agoI understand that things can go wrong and there can be security issues, but I see at least two other issues: 1. what if, ChadGPT style, ads are added to the answers (like OpenAI said it'd do, hence the new "ChadGPT" name)? 2. what if the current prices really are unsustainable and the thing goes 10x? Are we living some golden age where we can both query LLMs on the cheap and not get ad-infected answers? I read several comments in different threads made by people saying: "I use AI because search results are too polluted and the Web is unusable" And I now do the same: "Gemini, compare me the HP Z640 and HP Z840 workstations, list the features in a table" / "Find me which Xeon CPU they support, list me the date and price of these CPU when they were new and typical price used now". How long before I get twelve ads along with paid vendors recommendations?
- FuckButtons 8mo agoI asked Gemini deep research to project when that will likely happen based on historical precedent. It guessed October 2027.
- spiderice 8mo ago> what if the current prices really are unsustainable and the thing goes 10x? Where does this idea come from? We know how much it costs to run LLMs. It's not like we're waiting to find out. AI companies aren't losing money on API tokens. What could possibly happen to make prices go 10x when they're already running at a profit? Claude Max might be a different story, but AI is going to get cheaper to run. Not randomly 10x for the same models.
- 8mo ago
- narmiouh 8mo agoI feel like a lot of non technical people who are vibe coding or vibe using these models, focus on hallucinations and believe that as the hallucinations are reduced in benchmarks, and over estimate their ability to create safe prompts that will keep these models in line. I think most people fail to estimate the real threat that malicious prompts can cause because it is not that common, its like when credit cards were launched, cc fraud and the various ways it could be perpetrated followed not soon after. The real threats aren’t visible yet but rest assured there are actors working to take advantage and many unfortunate examples will be seen before general awareness and precaution will prevail….
- ed_mercer 8mo agoIf you run openclaw on a spare laptop or VM and give it read only access to whatever it needs, doesn’t that eliminate most of the risk?
- AlexCoventry 8mo agoIf you're letting it communicate with the outside world, you risk the leak and abuse of anything sensitive in the data it has access to.
- ttul 8mo agos/risk/guarantee (given sufficient time)/
- eskaytwo 8mo agoThanks! Was hoping someone would do something more sane like this. Openclaw is very useful, but like you I share the sentiment of it being terrifying, even before you introduce the social network aspect. My Mac mini is currently literally switched off for this very reason.
- Bnjoroge 8mo agoCan we start putting disclaimers beside the title on AI-generated projects? Extremely fatiguing to read through it and realize it’s mostly LLM slop.
- suprstarrd 8mo agoIt blows my mind that this wasn't the thought process going in. Thank you for doing this!
- raphaelmolly8 8mo ago[dead]
- singular_atomic 8mo agoHackernews needs a mute keywords feature. Clawd/molt-slop is mass AI psychosis on steroids.
- fragmede 8mo agoIf only there was some sort of thing that would help you build that for yourself.
- nsonha 8mo agowhat's the difference between this and just exposing opencode running in colima or whatever through tailscale? I got the impression that Clawdbot adds the headless browser (does it?) and that's the value. Otherwise even "nano"claw seems like uneccessary bloat for me.
- sothatsit 8mo agoThe idea of avoiding config files, and having the config be getting your agent to modify its own codebase, is fascinating. My gut reaction says that I don't like it, but it is such an interesting idea to think about.
- walterbell 8mo ago> found it useful but running it scares https://maordayanofficial.medium.com/the-sovereign-ai-security-crisis-42-000-exposed-openclaw-instances-and-the-collapse-of-1e3f2687b951 https://maordayanofficial.medium.com/the-sovereign-ai-securi... At least 42,665 instances are publicly exposed on the internet, with 5,194 instances actively verified as vulnerable through systematic scanning.. The narrative that “running AI locally = security and privacy” is significantly undermined when 93% of deployments are critically vulnerable. Users may lose faith in self-hosted alternatives.. Governments and regulators already scrutinizing AI may use this incident to justify restrictions on self-hosted AI agents, citing security externalities.
- prophesi 8mo agoAm I correct that after cloning down the project, you open the directory in Claude Code, then "execute" a markdown file instructing a nondeterministic LLM to set everything up for you in natural language?
- te_chris 8mo agoPosthog is doing this now for project setup
- Spacemolte 8mo agoThe premise of the project is he doesn't want to run code he doesn't know + in an insecure way, so having the setup step to install dependencies etc, done by an LLM seems like an odd choice. Like what part about the setup step is so fluffy and different per environment, that using an LLM for it makes sense?
- dsrtslnd23 8mo agocan NanoClaw be used to participate in ClackerNews?
- theptip 8mo ago> AI-native. No installation wizard; Claude Code guides setup. No monitoring dashboard; ask Claude what's happening. No debugging tools; describe the problem, Claude fixes it. > Skills over features. Contributors shouldn't add features (e.g. support for Telegram) to the codebase. Instead, they contribute claude code skills like /add-telegram that transform your fork. I’m interested to see how this model pans out. I can see benefits (don’t carry complexity you don’t need) and costs (how do I audit the generated code?). But it seems pretty clear that things will move in this direction in ‘26 with all the vibe coding that folks are enjoying. I do wonder if the end state is more like a very rich library of composable high-order abstractions, with Skills for how to use them - rather than raw skills with instructions for how to lossily reconstruct those things.
- charcircuit 8mo agoI think the more interesting question is were tools the right abstraction. What is the implication of having only a single "shell" tool. Should the infinite possibilities to few happen by the AI having limited tools or should whatever the shell calls have the limitations applied there. Tools in a way are redundant.
- Tepix 8mo agoA personal assistant that runs in the standard cloud (anthropic in this case) is madness. That‘s the hill I‘m willing to die on. Run it locally or use a cloud provider you can deeply trust.
- maximgeorge 8mo ago[dead]
- chaostheory 8mo agoFor anyone else worried about running openclaw, in my case I just bought openclaw its Mac mini and I gave openclaw its own accounts including GitHub. It makes many of the security concerns moot. Of course, I could go further and give openclaw its own internet access as well.
- aitchnyu 8mo agoThat Baileys api for Whatsapp may (AFAICT) put you in thin ice with Meta. Is there a cheap legit alternative? https://baileys.wiki/docs/intro/ https://baileys.wiki/docs/intro/
- dandaka 8mo agoI was using WAHA. It is an abstraction layer with a proper API on top. It supports many engines like Baileys and Whatsmeow (golang). Unfortunately, all those solutions are shaky and could lead to a ban on your account. https://waha.devlike.pro/ https://waha.devlike.pro/
- reassess_blind 8mo agoWhat’s the difference between this, and just running Claude Code in —dangerously-skip-permissions mode in a container and accessing remotely via ssh? I’m confused as to what these claw agents actually offer.
- randomtoast 8mo agoThe README.md describes it as: WhatsApp (baileys) --> SQLite --> Polling loop --> Container (Claude Agent SDK) --> Response So they basically put a Wrapper around Claude in a Container, which allows you to send messages from WhatsApp to Claude, and act somewhat as if you had a Siri on steriods.
- reassess_blind 8mo agoFound the spec here: https://github.com/gavrielc/nanoclaw/blob/main/docs/SPEC.md https://github.com/gavrielc/nanoclaw/blob/main/docs/SPEC.md The scheduled tasks seem like the major functional difference. Pretty cool. Has anyone tried Anthropic’s “Cowork”? How does that compare?
- esskay 8mo agoStupid stuff openclaw did for me: - Created its own github account, then proceeded to get itself banned (I have no idea what it did, all it said was it created some new repos and opened issues, clearly it must've done a bit more than that to get banned) - Signed up for a Gmail account using a pay as you go sim in an old android handset connected with ADB for sms reading, and again proceeded to get itself banned by hammering the crap out of the docs api - Used approx $2k worth of Kimi tokens (Thankfully temporarily free on opencode) in the space of approx 48hrs. Unless you can budget $1k a week, this thing is next to useless. Once these free offers end on models a lot of people will stop using it, it's obscene how many tokens it burns through, like monumentally stupid. A simple single request is over 250k chars every single time. That's not sustainable.
- arccy 8mo agofiling spam issues can easily get the account banned if it annoys the wrong maintainers.
- esskay 8mo agoIn that case I'm glad they banned it, had no idea it was going to do something so stupid!
- swordsith 8mo ago> and again proceeded to get itself banned by hammering the crap out of the docs api > Used approx $2k worth of Kimi tokens Holy shit dude you really should rethink your life decisions this is NUTS
- shawabawa3 8mo ago> (Thankfully temporarily free on opencode) they paid $0, it's all VC money printing for now
- swordsith 8mo agoThe carbon and electricity would like to have word
- ivanstepanovftw 8mo agoWhere are those 500 lines of code?
- QuadmasterXLII 8mo agoEarlier that day: “hey Claude how many lines of code are in this project? 500? Great!”
- charliecs 8mo ago[dead]
- evrenesat 8mo ago> No daemons, no queues, no complexity. Last time I checked, having a continuously running background process considered as a daemon. Using SQLite as back-end for storing the jobs also doesn't make it queueless. /nit
- retired 8mo agoI looked at Clawdbot. Perhaps my life is so boring that managing it takes little time but I see zero reasons to run it.
- written-beyond 8mo agoI read your comment, then your username. I CAN'T BELIEVE THIS USERNAME WAS CLAIMED 14 DAYS AGO! Good catch!
- retired 8mo agoTook me around ten minutes of finding a simple username that wasn't taken.
- MORPHOICES 8mo ago[dead]
- elgrantomate 8mo agodef appreciate this more compact approach; everything is an experiment rn. I realize you used Claude Agent SDK on purpose but I'd really like to this to be agent agnostic. Maybe I'll figure that out...
- river_otter 8mo agoGreat idea and name the danger here which I'll be interested to track is how do you keep this "nano"? Since it's built for you, you'll continue adding features i assume which over time will make this not very nano. I guess I'm wondering if there could be some small design tweaks of the repo that make this usable as a long term "fork the base and make it your own" concept
- stronglikedan 8mo agoA personal implementation will always be "nano" compared to the full OpenClaw suite. As with literally everything, it's all relative.
- jimminyx 8mo agoI will keep the source code as a minimal implementation that has the core capabilities that made Clawdbot/OpenClaw useful: chat with it via messaging app (only one channel included out of the box), memory (minimal implementation that leverages CLAUDE.md and the filesystem), cron jobs, browser. If I want to add additional capabilities for myself, I'll contribute them to the project as skills for claude code to modify the code base, rather than directly to the source. I actually want to reduce the size of the base implementation and have a PR open to strip out 300-400 LOC
- moi2388 8mo ago500 lines? Single files in that repo already have more than 500 lines.
- pulkas 8mo agoThis violates the Claude Code subscription terms of service, so please be careful. This project violates Claude Code's Terms of Service by automating Claude to create an unattended chatbot service that responds to third-party messaging platforms (WhatsApp, and what you add ...). The exact issues: 1. Automated, unattended usage - The system runs as a background service (launchd) that automatically responds to WhatsApp messages without human intervention (src/index.ts:549-574) 2. Building a bot service - This creates a persistent bot that monitors messages and responds automatically, which violates restrictions on building derivative services on top of Claude 3. Third-party platform integration - Connecting Claude to WhatsApp (or other messaging platforms) to create an automated assistant service isn't an authorized use case. The README itself reveals awareness of this issue at line 41: **No ToS gray areas.** Because it uses Claude Agent SDK natively with no hacks or workarounds, using your subscription with your auth token is completely legitimate (I think). No risk of being shut down for terms of service violations (I am not a lawyer). The defensive tone ("I think", "I am not a lawyer") indicates uncertainty about legitimacy. While using your own credentials doesn't automatically make automated bot services compliant—Anthropic's TOS restricts using their products to build automated chatbot services, regardless of authentication method. The core violation: transforming Claude Code into an automated bot service that operates without human intervention, which is explicitly prohibited.
- jimminyx 8mo agoInteresting. Again, not a lawyer, but all of this is a bit murky and not sure it applies. 1. Usage is not automated and unattended - it only responds to messages that are sent to it with a specific prefix "Andy:" 2. This is not a bot service. It is not crawling twitter and responding to posts. Hard to see how sending it messages through WhatsApp is any different than through ssh via the terminal 3. I don't think a custom piece of software running on my computer that pipes data from a program into the Agents SDK is a third party "platform" integration. How is this different from running Agents SDK as part of a CI process?
- ramoz 8mo agoNot seeing how the sandbox prevents anything really. The point of OpenClaw is to connect out to different systems.
- FreePalestine1 8mo agoSure but at least it protects against unauthorized free-for-all access on your host system. If you want to explicitly give it access to external APIs over the internet that's a risk you personally are taking. It's really smart to run something like this in a sandbox, especially in the current beta/experimentation phase.
- deadbabe 8mo agoTo those who complain about these bots and the security concerns they raise, you basically have two options: 1. You can live in the future, and be at the bleeding edge of the latest AI tech, reaping the benefits. Be part of the solution. 2. You can stay in the past and get left behind, at the mercy of those who took the risks.
- mathfailure 8mo agoThe 2. Thank you.
- ccheshirecat 8mo agoi installed clawdbot twice but didn't really use it because i couldn't wrap my head around the skills and plugins, this looks so much more managable. and +1 for apple containers
- fernandolugo 8mo ago[dead]
- srinath693 8mo agoThe "skills not features" contribution model is the most interesting part of this. Instead of a project that grows into another 52-module beast, contributors teach Claude how to transform the codebase per-user. It's basically contributing build instructions instead of build artifacts. If it actually works in practice, it's a genuinely novel approach to keeping small projects small.
- jimminyx 8mo agoThanks! I believe that's where software is going. Just need Karpathy to give it a name so it can take off ;)
- zizheruan 8mo ago[dead]
- hitsmaxft 8mo agohttps://github.com/gavrielc/nanoclaw/commit/22eb5258057b49a08f4ea18c8e15df289e8fd884 https://github.com/gavrielc/nanoclaw/commit/22eb5258057b49a0... Is this inserting an advertisement into the agent prompt?