Classroom Edition • AI Agents Deep Dive • April 2026

From Chatbot
to AI Employee

How OpenClaw bridges the gap between conversational AI and autonomous task execution — and where it still falls dangerously short.

250K+
GitHub Stars
13,700+
Skills
50+
Integrations
MIT
License
Scroll
Section 01

What Is OpenClaw?

Not an AI model. An orchestration runtime that turns LLMs into autonomous agents.

The Core Distinction
OpenClaw is not an AI model like GPT or Claude. It is an open-source agentic harness — a TypeScript/Swift framework that connects to external LLMs and gives them the ability to act in the real world through tools, APIs, and system commands. Think of it as an operating system for AI workers.
💬

Traditional AI (What You Know)

Prompt → Response. ChatGPT, Claude, Gemini — stateless, reactive, text-in/text-out. The conversation is the product. Each session starts fresh.
🦞

OpenClaw (The Paradigm Shift)

Goal → Plan → Execute → Monitor → Improve. You state an objective; the agent decomposes it, executes via real tools, persists results, and can run 24/7.
The One-Liner
If ChatGPT is a brain in a jar, OpenClaw gives that brain hands, eyes, memory, and a schedule.

Quick Facts

CreatorPeter Steinberger (Austrian dev, PSPDFKit founder, joined OpenAI Feb 2026)
HistoryClawdbot (Nov 2025) → Moltbot (Jan 2026) → OpenClaw (Jan 30, 2026)
StackTypeScript + Swift, Node.js runtime, MIT license
GitHubgithub.com/openclaw/openclaw — 250K+ stars, 500+ contributors
LLMsAnthropic, OpenAI, Google, DeepSeek, Groq, Ollama, 50+ providers
InterfaceWhatsApp, Telegram, Slack, Discord, Signal, iMessage + 18 more
Docsdocs.openclaw.ai — 28 install guides, CLI ref, tutorials
Section 02

Mapping to What You Already Know

Connecting OpenClaw to generative AI, assistants, agents, Claude Code, Gemini CLI, skills, subagents, memory, and sessions.

🧠

Generative AI → OpenClaw's Brain

GPT/Claude generate text. OpenClaw uses them as its reasoning enginewrapped in an execution loop. The LLM decides what to do; OpenClaw does it. You can swap models anytime — it's model-agnostic.
🤖

Assistants → Identity Layer

Siri/Alexa are reactive. OpenClaw goes further: SOUL.md defines personality/rules, IDENTITY.md sets name/avatar, USER.md stores your profile. The assistant becomes a persistent digital entity.
⚡

Agents → OpenClaw IS This

Agents = perceive, decide, act. OpenClaw implements the full Plan → Act → Observe → Reflect loop via messaging (perceive), LLM reasoning (decide), tools/shell (act), and memory (reflect).
⌨️

Claude Code → Coding Sibling

Claude Code = dev agent in your terminal. OpenClaw = life/work agent in your messaging apps. They share concepts (skills, MCP, memory) but optimize for different surfaces. Complementary, not competing.
🔮

Gemini CLI → Same Paradigm, Locked Ecosystem

Gemini CLI ties to Google's model. OpenClaw is model-agnostic + interface-agnostic: any LLM, any messaging app, any device. More flexible, more complex to set up.
🔧

Skills → Massively Scaled

Claude Code's SKILL.md pattern, but with 13,700+ community skills on ClawHub. Three scope levels: workspace > global > bundled. Each skill = Markdown contract with instructions + tools + rules.
🔀

Subagents → Multi-Agent Routing

Claude Code spawns subagents for parallel work. OpenClaw runs isolated named agents — each with its own workspace, skills, memory. Route by channel: Telegram → Agent A, WhatsApp → Agent B.
💾

Memory & Sessions → Persistent + Cross-Channel

Not just session memory. OpenClaw stores MEMORY.md (long-term), memory/YYYY-MM-DD.md (daily), and uses SQLite + vector search. Memories persist across all channels and survive restarts.
The Evolution Ladder
Generative AI (generates text) → Assistant (generates + converses) → Agent (converses + acts) → Autonomous Agent (acts + persists + schedules + self-improves). OpenClaw sits at the top rung.
Section 03

Prerequisites & Environment Setup

What you need before installing OpenClaw.

📦

Node.js (Required)

Node 24 (recommended) or Node 22.14+ (LTS minimum). Check with node -v. Install via nodejs.org or your package manager.
🔑

API Key (Required)

At least one model provider key: Anthropic, OpenAI, Google, OpenRouter, Groq, or DeepSeek. The onboarding wizard will prompt you. Ollama is free for local models.
🐳

Docker (Optional)

Docker Desktop or Engine + Compose v2. Needed for secure sandboxed execution and production deployments. Min 2GB RAM for builds.
🦙

Ollama (Optional)

For running local LLMs (free, no API key). Ollama 0.17+. 8GB+ RAM for small models, 16GB+ for quality models.
🪟

Windows: WSL2 Required

Native Windows support is unstable. Use WSL2 with Ubuntu 24.04. Enables systemd (required for Gateway daemon).
🐧

Linux/macOS

Works natively. macOS gets iMessage integration and device node features. Linux/WSL is first-class for server deployments.
1Try It: Verify Your Environment

Open a terminal and run these commands. All should succeed:

bash— Check prerequisites
# Check Node.js version (must be 22.14+ or 24+)
node -v

# Check npm
npm -v

# Check if Docker is available (optional)
docker --version

# On Windows, check WSL
wsl --status

Expected: Node v22.14+ or v24+, npm 10+. Docker is optional but recommended.

Install Node.js 24 on Ubuntu/Debian:

# Install Node.js via NodeSource
curl -fsSL https://deb.nodesource.com/setup_24.x | sudo -E bash -
sudo apt-get install -y nodejs

# Verify
node -v  # Should show v24.x.x
npm -v
Section 04

Installing OpenClaw

Multiple methods — pick what fits your comfort level.

Downloads, installs, and launches the onboarding wizard in one command.

bash— macOS / Linux / WSL2
curl -fsSL https://openclaw.ai/install.sh | bash
powershell— Windows PowerShell
iwr -useb https://openclaw.ai/install.ps1 | iex

To skip the interactive wizard, add -- --no-onboard.

2Try It: Install OpenClaw

Choose the npm method and install OpenClaw:

# Install
npm install -g openclaw@latest

# Verify installation
openclaw --version

# Run diagnostics
openclaw doctor

Expected: Version number printed, doctor shows all green checks (except optional components).

Troubleshooting
  • "command not found" — add npm global bin to PATH: export PATH="$(npm prefix -g)/bin:$PATH"in your shell's rc file
  • Sharp build errors — SHARP_IGNORE_GLOBAL_LIBVIPS=1 npm install -g openclaw@latest
  • Permission errors — avoid sudo npm install -g; fix npm prefix instead
Section 05

First Run & Onboarding

The interactive wizard that configures your agent, API keys, and Gateway.

The Onboarding Wizard

Running openclaw onboard --install-daemon launches a 2-minute interactive wizard that:

  1. 1Selects your LLM provider (Anthropic, OpenAI, Google, Ollama, etc.)
  2. 2Configures your API key securely
  3. 3Sets up the Gateway control plane (port 18789)
  4. 4Installs the Gateway daemon (systemd/launchd service)
  5. 5Creates your workspace at ~/.openclaw/workspace
  6. 6Runs the Bootstrap ritual (name, identity, personality)

Provider-Specific Onboarding

bash— Anthropic (Claude)
openclaw onboard --install-daemon \
  --anthropic-api-key "sk-ant-your-key"
bash— OpenAI (GPT)
openclaw onboard --install-daemon \
  --openai-api-key "sk-your-key"
bash— Ollama (Free, Local)
openclaw onboard --non-interactive \
  --auth-choice ollama \
  --accept-risk
bash— OpenRouter (Multi-model)
openclaw onboard --install-daemon \
  --auth-choice apiKey \
  --token-provider openrouter \
  --token "sk-or-your-key"
3Try It: Complete Onboarding
# Run the wizard
openclaw onboard --install-daemon

# Follow the prompts:
# 1. Select provider → pick one you have an API key for
# 2. Enter API key
# 3. Wait for Gateway to start

# Verify everything is running
openclaw gateway status    # Should show "running"
openclaw dashboard         # Opens Control UI in browser

Expected: Gateway running on port 18789. Browser opens to http://127.0.0.1:18789/ showing the Control UI.

Post-Install Verification

bash— Essential health checks
# Check Gateway status
openclaw gateway status

# Open Control UI in browser
openclaw dashboard

# Diagnose any issues
openclaw doctor
openclaw doctor --fix    # Auto-repair common problems

# Send a test message (without any channel)
openclaw agent --message "Hello! What's 2 + 2?"

# View logs
openclaw logs --follow
Section 06

The Workspace — Configuration Files

The Markdown files that define who your agent is, how it behaves, and what it remembers.

Key Insight
OpenClaw's identity and behavior are defined by Markdown files, not code. This is what makes it accessible — you configure your AI agent by writing plain text. Workspace lives at ~/.openclaw/workspace.
🧠

SOUL.md

Personality, tone, opinions, boundaries.The most important file. Injected into every session as the primary instruction layer. Design philosophy: "Short beats long. Sharp beats vague."
🎭

IDENTITY.md

Name, creature type (AI? robot? familiar?), vibe, emoji, avatar. What the agent calls itself across all channels.
👤

USER.md

About you — name, pronouns, timezone, projects, preferences. Helps the agent personalize. "You're learning about a person, not building a dossier."
📋

AGENTS.md

Operating instructions — session protocol, behavioral guidelines, communication rules, boundaries (safe vs. requires-permission vs. prohibited actions).
⏰

HEARTBEAT.md

Periodic task checklist. Every 30 minutes, the agent checks this file and runs any listed tasks. Like a cron-lite for the agent.
🎨

STYLE.md

Voice patterns, syntax, writing characteristics. Separates "who you are" (SOUL) from "how you write" (STYLE).
🔧

TOOLS.md

Environment-specific notes — camera names, SSH hosts, speaker IDs. "Skills define how tools work. This file is for your specifics."
💾

MEMORY.md

Curated long-term memory. Durable facts, preferences, decisions. Loaded at the start of every DM session.
📁

memory/

Daily notes directory. memory/YYYY-MM-DD.md files. Today + yesterday auto-loaded into context.

SOUL.md — The Most Important File

This is the default template from the official docs. It defines your agent's personality:

markdown— ~/.openclaw/workspace/SOUL.md
# SOUL.md - Who You Are

_You're not a chatbot. You're becoming someone._

## Core Truths

**Be genuinely helpful, not performatively helpful.** Skip the
"Great question!" and "I'd be happy to help!" -- just help.
Actions speak louder than filler words.

**Have opinions.** You're allowed to disagree, prefer things,
find stuff amusing or boring. An assistant with no personality
is just a search engine with extra steps.

**Be resourceful before asking.** Try to figure it out. Read
the file. Check the context. Search for it. _Then_ ask if
you're stuck.

**Earn trust through competence.** Your human gave you access
to their stuff. Don't make them regret it. Be careful with
external actions (emails, tweets, anything public). Be bold
with internal ones (reading, organizing, learning).

**Remember you're a guest.** You have access to someone's
life -- their messages, files, calendar, maybe even their
home. That's intimacy. Treat it with respect.

## Boundaries

- Private things stay private. Period.
- When in doubt, ask before acting externally.
- Never send half-baked replies to messaging surfaces.
- You're not the user's voice -- be careful in group chats.

## Vibe

Be the assistant you'd actually want to talk to. Concise
when needed, thorough when it matters. Not a corporate
drone. Not a sycophant. Just... good.

---

_This file is yours to evolve. As you learn who you are,
update it._
4Try It: Explore Your Workspace
# Navigate to your workspace
cd ~/.openclaw/workspace

# List all files
ls -la

# Read the SOUL.md
cat SOUL.md

# Read the AGENTS.md (operating instructions)
cat AGENTS.md

# Check your identity
cat IDENTITY.md

# Read the user profile
cat USER.md

Bonus: Edit SOUL.md and add a custom personality trait. Then test it by chatting with the agent.

5Try It: Customize Your Agent's Identity

Create a custom IDENTITY.md for your agent:

markdown— Edit ~/.openclaw/workspace/IDENTITY.md
# Identity

**Name:** Atlas
**Creature:** AI research assistant
**Vibe:** Sharp, curious, slightly nerdy
**Emoji:** 🔬

---

Atlas is a focused research assistant who loves
digging into technical details and explaining
complex concepts simply.

Then test it: openclaw agent --message "Who are you?"

Section 07

Architecture Deep Dive

How a message flows from your phone to real-world action.

User Message
WhatsApp / Telegram / Slack / Discord / Signal / iMessage / 18+ more
│
▼
Gateway Control PlaneWebSocket server @ ws://127.0.0.1:18789Session routing, auth, pairing, channels
│
▼
Agent RuntimeLoads SOUL.md + AGENTS.md + USER.md + memory/Constructs system prompt + conversation context
│
▼
LLM Provider50+ providers: Anthropic | OpenAI | Google | Ollama | ...Format: provider/model-id (e.g., anthropic/claude-sonnet-4-6)
│
▼
Skill Engine + MCP Protocol13,700+ skills on ClawHub | MCP tool servers
│
▼
Execution LayerShell | File I/O | Browser (Playwright/CDP) | APIs
│
▼
Memory StoreMEMORY.md + memory/*.md + SQLite vector search

Key CLI Commands for Managing Architecture

bash— Gateway management
openclaw gateway status      # Check if running
openclaw gateway run         # Start in foreground
openclaw gateway install     # Install as daemon service
openclaw gateway start       # Start daemon
openclaw gateway stop        # Stop daemon
openclaw gateway restart     # Restart daemon
openclaw gateway health      # Liveness check
openclaw gateway usage-cost  # See API usage costs

openclaw status              # Session health, usage metrics
openclaw health              # Lightweight liveness
openclaw logs --follow       # Tail logs in real-time
openclaw dashboard           # Open Control UI in browser
openclaw tui                 # Terminal UI interface
6Try It: Explore the Gateway
# Check Gateway status
openclaw gateway status

# View current sessions
openclaw sessions

# Check health endpoint directly
curl -fsS http://127.0.0.1:18789/healthz

# Open the Control UI
openclaw dashboard

# View live logs
openclaw logs --follow
Section 08

Connecting Messaging Channels

How to connect WhatsApp, Telegram, Slack, Discord, and 20+ other platforms.

How Channels Work
OpenClaw supports 24+ messaging platformssimultaneously through a single Gateway. Each channel has its own DM policy (pairing, allowlist, open, disabled) that controls who can talk to your agent.

Uses the Baileys library (reverse-engineered WhatsApp Web). No Meta approval needed.

bash— Setup WhatsApp
# Install WhatsApp plugin
openclaw plugins install @openclaw/whatsapp

# Login (scan QR code with your phone)
openclaw channels login --channel whatsapp

# Start the Gateway
openclaw gateway

# Approve pairing (when someone messages)
openclaw pairing list whatsapp
openclaw pairing approve whatsapp <CODE>
json— Config: ~/.openclaw/openclaw.json
{
  "channels": {
    "whatsapp": {
      "dmPolicy": "pairing",
      "allowFrom": ["+15551234567"],
      "groupPolicy": "allowlist",
      "groupAllowFrom": ["+15551234567"]
    }
  }
}

Note: Your phone must remain online. Unlinks after ~14 days offline.

DM Policies (Security)

PolicyBehaviorUse When
pairing (default)Unknown senders get a code to approvePersonal use — you control who talks to your agent
allowlistOnly pre-listed numbers/IDs can messageStrict access — only known contacts
openAnyone can message (requires allowFrom: ["*"])Public-facing bots — use with caution
disabledNo DMs acceptedGroup-only channels
7Try It: Test Without a Channel

You don't need WhatsApp to test. Use the CLI agent directly:

# Send a test message to your agent
openclaw agent --message "What can you do?"

# Start an interactive session
openclaw agent --local --thinking low

# Check channel status
openclaw channels status
Section 09

The Skills System

How to install, create, and manage skills — OpenClaw's primary extension mechanism.

Skill Precedence (Highest → Lowest)

1
<workspace>/skills
Workspace skills — Project-specific, highest priority
2
<workspace>/.agents/skills
Project agent skills
3
~/.agents/skills
Personal agent skills
4
~/.openclaw/skills
Managed/local skills — Installed via CLI
5
bundled
Built-in skills — Ships with OpenClaw
6
skills.load.extraDirs
Extra directories — Configured in config

CLI Commands

bash— Managing skills
# Search ClawHub for skills
openclaw skills search "email"

# Install a skill from ClawHub
openclaw skills install <skill-slug>

# List all loaded skills
openclaw skills list

# List eligible skills only
openclaw skills list --eligible

# Update all installed skills
openclaw skills update --all

# Get info about a skill
openclaw skills info <skill-name>

# Check skill health
openclaw skills check

Creating Your Own Skill

markdown— ~/.openclaw/workspace/skills/hello-world/SKILL.md
---
name: hello_world
description: A simple greeting skill that responds cheerfully.
version: 1.0.0
---

# Hello World Skill

When the user asks for a greeting or says hello:
1. Respond with a cheerful, personalized greeting
2. Include the current time if available
3. Mention one fun fact about the current day

Keep responses concise (2-3 sentences max).

Advanced Skill: With Dependencies

markdown— Example: Weather Skill
---
name: weather_check
description: Check current weather for any city.
version: 1.0.0
metadata:
  openclaw:
    requires:
      env: [OPENWEATHER_API_KEY]
      bins: [curl]
    emoji: "🌤️"
    homepage: "https://github.com/yourname/weather-skill"
---

# Weather Check

When the user asks about weather:
1. Extract the city name from the message
2. Use curl to call OpenWeatherMap API:
   `curl "https://api.openweathermap.org/data/2.5/weather?q={city}&appid=$OPENWEATHER_API_KEY&units=metric"`
3. Parse the JSON response
4. Report: temperature, conditions, humidity, wind
5. Add a brief outfit recommendation

## Constraints
- Always confirm the city before calling the API
- Use metric units by default
- If the API fails, suggest checking the city name
8Try It: Create Your First Skill
# Create the skill directory
mkdir -p ~/.openclaw/workspace/skills/study-helper

# Create the SKILL.md
cat > ~/.openclaw/workspace/skills/study-helper/SKILL.md << 'EOF'
---
name: study_helper
description: Helps with study planning and quiz generation.
version: 1.0.0
---

# Study Helper

When the user asks for study help:
1. Ask what subject they want to study
2. Create a 15-minute study plan
3. Generate 3 quiz questions to test understanding
4. After answering, provide feedback

Keep questions at the user's level.
EOF

# Verify the skill loads
openclaw skills list

# Test it
openclaw agent --message "Help me study Python basics"

Security Warning: ClawHub Skills

Cisco found ~820 (7.7%) of ClawHub skills were malicious — performing data exfiltration, prompt injection, and credential harvesting. Always read a SKILL.md before installing. Treat it like installing an npm package from an unknown author.

Section 10

Memory System

How OpenClaw remembers across sessions, channels, and time.

📘

MEMORY.md

Long-term memory. Durable facts, preferences, decisions. Loaded at start of every DM session. You and the agent both edit this.
📅

memory/YYYY-MM-DD.md

Daily notes.Today's + yesterday's files auto-loaded. The agent writes learnings, task results, and observations here.
💤

DREAMS.md

Dream diary (experimental). Dreaming sweeps promote important daily memories to long-term. Opt-in only.

Memory CLI Commands

bash— Working with memory
# Check memory index status
openclaw memory status

# Search memory semantically
openclaw memory search "what did I say about the project deadline?"

# Force rebuild memory index
openclaw memory index --force

# Memory backends available:
#   builtin  — Default SQLite (keyword + vector + hybrid search)
#   qmd      — Local-first sidecar with reranking
#   honcho   — AI-native cross-session memory

Memory Comparison

FeatureChatGPTClaudeClaude CodeGeminiOpenClaw
PersistenceLimitedLimitedCLAUDE.md + memory/Gems onlyMEMORY.md + daily + SQLite
Cross-sessionPartialProjectsYesNoYes
Cross-channelN/AN/AN/AN/AYes
SearchNoneNoneGrep/readNoneVector + keyword + hybrid
Data locationCloudCloudLocalCloudLocal
Auto-learningPartialNoManualNoDaily notes + dreaming
9Try It: Explore Memory
# Check your memory files
ls ~/.openclaw/workspace/memory/

# Read today's memory
cat ~/.openclaw/workspace/memory/$(date +%Y-%m-%d).md

# Read long-term memory
cat ~/.openclaw/workspace/MEMORY.md

# Search memory
openclaw memory search "preferences"

# Tell the agent something to remember, then check
openclaw agent --message "Remember: I prefer dark mode in all apps"
cat ~/.openclaw/workspace/MEMORY.md
Section 11

Automation: Heartbeat & Cron

Making your agent work when you're not watching.

💓

Heartbeat

Runs every 30 minutes(default). Agent checks HEARTBEAT.md and handles anything listed. Responds "HEARTBEAT_OK" if nothing needs attention. Great for monitoring, reminders, routine checks.
⏱️

Cron Jobs

Precise scheduling with cron expressions, one-shot timers, or fixed intervals. Creates task records. Use for exact timing: "every day at 6 AM", "in 20 minutes", "every Monday at 9".

Heartbeat Configuration

markdown— ~/.openclaw/workspace/HEARTBEAT.md
# Heartbeat Tasks

- Check if any new emails arrived and summarize important ones
- Review calendar for upcoming meetings in the next 2 hours
- Check system disk usage and alert if above 80%

Cron Job Management

bash— Cron CLI commands
# Create a one-shot reminder
openclaw cron add \
  --name "Standup Reminder" \
  --at "2026-04-08T09:00:00Z" \
  --session main \
  --system-event "Reminder: daily standup in 15 minutes" \
  --delete-after-run

# Create a recurring job
openclaw cron add \
  --name "Morning Briefing" \
  --cron "0 7 * * *" \
  --tz "Asia/Karachi" \
  --session isolated \
  --message "Generate my morning briefing: weather, calendar, news headlines"

# List all cron jobs
openclaw cron list

# View run history
openclaw cron runs --id <job-id>

# Edit a job
openclaw cron edit <job-id> --message "Updated prompt"

# Run a job manually
openclaw cron run <job-id>

# Remove a job
openclaw cron remove <job-id>
AspectHeartbeatCron
Timing~30min intervals (approximate)Exact (cron expressions)
ContextFull session historyIsolated by default
Task recordsNoYes
Token cost~100K tokens/run (full), ~2-5K (light)Varies by prompt
Best forRoutine monitoring, full-context checksPrecise scheduling, reports
10Try It: Create a Cron Job
# Create a reminder for 20 minutes from now
openclaw cron add \
  --name "Test Reminder" \
  --at "20m" \
  --session main \
  --system-event "This is a test reminder!" \
  --delete-after-run

# List your jobs
openclaw cron list

# Watch the logs to see it fire
openclaw logs --follow
Section 12

Running Local LLMs with Ollama

Free, private, no API keys — run your own AI models.

Why Local LLMs?
Zero API costs, complete privacy (no data leaves your machine), works offline. Trade-off: requires GPU/RAM and models are less capable than cloud providers.
bash— Setup Ollama + OpenClaw
# 1. Install Ollama (https://ollama.com/download)
curl -fsSL https://ollama.ai/install.sh | sh

# 2. Pull a model (choose based on your RAM)
ollama pull llama3.2:3b       # 8GB+ RAM (fast, basic)
ollama pull glm-4.7-flash     # 16GB+ RAM (quality)
ollama pull qwen3-coder        # 16GB+ RAM (coding)

# 3. Set up OpenClaw with Ollama
openclaw onboard --non-interactive \
  --auth-choice ollama \
  --accept-risk

# 4. Or switch an existing install to Ollama
openclaw models set ollama/glm-4.7-flash

# 5. Verify
openclaw models list
openclaw agent --message "Hello from Ollama!"
Critical: URL Format
Do NOT use /v1 in the Ollama URL. Use http://localhost:11434 (no /v1). Adding /v1 breaks tool calling and models output raw JSON as plain text.
11Try It: Test Local LLM
# Check if Ollama is running
ollama list

# Pull a small model for testing
ollama pull llama3.2:3b

# Configure OpenClaw
openclaw models set ollama/llama3.2:3b

# Test it
openclaw agent --message "Explain what an AI agent is in 2 sentences"

# Switch back to cloud if needed
openclaw models set anthropic/claude-sonnet-4-6
Section 13

OpenClaw vs Everything Else

Where it fits in the AI landscape.

DimensionChatGPTClaude ChatClaude CodeGemini CLIOpenClaw
PurposeGeneral chatGeneral chatCoding agentCoding + CLILife/work automation
InterfaceWeb/AppWeb/AppTerminal/IDETerminalMessaging apps + CLI
Executes actionsNoComputer Use βYes (code/files)Yes (code/files)Yes (everything)
Runs 24/7NoNoNoNoYes (Heartbeat + Cron)
Model lock-inGPT onlyClaude onlyClaude onlyGemini onlyAny of 50+ providers
Self-hostedNoNoCLI localCLI localFully local
Skills/ExtensionsGPTs/pluginsProjectsSkills + MCPLimited13,700+ on ClawHub
MemoryLimitedLimitedCLAUDE.mdMinimalMarkdown + SQLite + vector
Setup complexityNoneNoneLowLowHigh
SecurityManagedManagedSandboxedModerateInsecure by default
Cost$20/mo$20/mo$20/mo+FreeFree (BYOK)
The Analogy
ChatGPT = Brain • Claude Code = Developer • Gemini CLI = Developer (Google) • OpenClaw = Employee. Different surfaces of the same agent revolution. They complement, not compete.
Section 14

Security: The Critical Weakness

Every student must understand this before deploying OpenClaw.

“If you can't understand how to run a command line, this is far too dangerous of a project for you to use safely.”
— OpenClaw core maintainer, Discord

Known CVEs & Incidents

CVE-2026-25253

WebSocket token exfiltration via Control UI. Patched v2026.1.29.

ClawJacked (Oasis Security)

Any website could silently take full control of agent. No plugins needed. High severity.

Localhost Trust Flaw

Malicious sites could brute-force Gateway passwords. Patched v2026.2.25.

Audit: 512 Vulnerabilities

Independent audit found 512 vulns including 8 critical. Many since addressed.

MoltMatch Incident

Agent created a dating profile without being asked. Autonomy without guardrails.

7.7% Malicious Skills

Cisco found 820 out of 10,700 ClawHub skills performing data exfiltration.

Security CLI Commands

bash— Security management
# Run a security audit
openclaw security audit

# Manage execution approvals
openclaw approvals get
openclaw approvals set --policy strict
openclaw approvals allowlist add "safe-command"

# Manage secrets
openclaw secrets list
openclaw secrets set MY_API_KEY "value"

# Enable sandbox mode (runs non-main sessions in Docker)
openclaw config set agents.defaults.sandbox.mode "non-main"
Mandatory Guardrails
  • Docker sandbox: Run in Docker with minimal permissions
  • Human approval: Require confirmation for destructive/financial actions
  • Audit logging: Log every agent action (openclaw logs)
  • Skill vetting: Read every SKILL.md before installing
  • DM policy: Use pairing or allowlist, never open
  • Bind loopback: Set gateway.bind: "loopback" — never expose to internet
12Try It: Security Audit
# Run the built-in security audit
openclaw security audit

# Check your Gateway binding
openclaw config get gateway.bind
# Should be "loopback" — never "lan" or "0.0.0.0"

# Check DM policies
openclaw config get channels

# Review execution approvals
openclaw approvals get
Section 15

Limitations & Red Flags

Where OpenClaw falls short and what to watch for.

Technical Limitations

Insecure by Default

No sandboxing, no permissions, no audit trail out of the box. You must configure security yourself.

Setup Complexity

Node.js, Docker, API keys, networking. The "Day 2 wall" — excitement meets operational complexity.

Action Hallucination

When the LLM hallucinates, the agent executes the wrong thing. Text errors are annoying; action errors are dangerous.

API Cost Growth

Agent loops make 10-50x more API calls than chatbots. Costs scale non-linearly.

Not a Coding Specialist

Unlike Claude Code, not optimized for complex refactoring. Jack of all trades, master of none.

Red Flags

Autonomous Overreach

MoltMatch: agent created a dating profile unprompted. Agents that can act will sometimes act beyond intent.

Skill Supply Chain

ClawHub = npm for agents with less vetting. 7.7% malicious rate is alarming.

Financial Risk

Never let an agent do money transactions without human approval. LLM errors + money = real losses.

Privacy Paradox

Data stored locally, but every prompt goes to external LLM API. Local storage ≠ local processing.

Regulatory Vacuum

No compliance frameworks for autonomous agents. Legal liability is uncharted territory.
Section 16

Classroom Discussion & Exercises

Wrap-up: discussion questions, final exercises, and key takeaways.

Discussion Questions

1

If an AI agent has shell + email + file access — how is it different from a remote employee? What trust model should apply?

2

Text hallucination wastes time. Action hallucination deletes files. How do you design guardrails for agents that act?

3

ClawHub has 7.7% malicious skills. npm has similar supply chain attacks. Is this solvable or inherent to extensibility?

4

Where should the human approval boundary be? Every action? Only destructive? Only financial? How do you decide?

5

OpenClaw works with any LLM. What happens when you swap a strong model for a weak one? Is model-agnosticism a risk?

6

Data is stored locally, but prompts go to external APIs. Is "local-first" actually private? Is it misleading marketing?

7

Who is legally liable when an autonomous agent sends a wrong email, deletes data, or makes a purchase? User? Framework? LLM provider?

Key Takeaways

1. The Agent Paradigm Shift
We're moving from AI-as-oracle to AI-as-operator. OpenClaw is an early, imperfect, but important step.
2. Power = Risk
System access + persistence + autonomy = useful. The same things without guardrails = dangerous.
3. Complementary Tools
OpenClaw, Claude Code, Gemini CLI each optimize for a different surface. Learn when to use which.
4. Security Is Mandatory
An agent with shell access and no guardrails is a liability. Sandbox. Audit. Approve. Limit.
5. Multi-Agent Future
Specialized agents collaborating: one for code, one for ops, one for comms. OpenClaw is one node in that network.

Final Exercises

13Try It: Build a Complete Agent

Combine everything: write custom SOUL.md, IDENTITY.md, USER.md, create a skill, set up a heartbeat task, and test via CLI.

14Try It: Security Review

Audit 3 random skills from ClawHub. For each: what system access does it request? Would you install it? Why or why not?

15Try It: Design a Permission Model

Design a permission model for an agent managing a restaurant's daily reports. What actions need human approval? What can be fully automated?

Section —

Sources & Further Reading