Index / Carapace · updated Oct 2, 2026
Carapace
puremachinery/carapace · healthy · rank 39 of 43 by stars
A security-hardened Rust rewrite of the OpenClaw personal assistant concept, built explicitly to counter the January 2026 OpenClaw vulnerability disclosures. It pairs a signed WASM plugin runtime with OS-level sandboxing and encrypted secret storage for a genuinely locked-down local agent.
Facts
Repository
Runtime
Posture
Community
Security breakdown
Composite 92 / 100 · how these are scored
higher is safer
higher is safer
higher is safer
higher is safer
higher is riskier
Model access
Read from the repository, not written by a model · 46 files examined
5 providers · runs locally · custom endpoint
Pinned models
gpt-5.5 released 2026-04-24 — 5 months old (from the public model catalogue)
Pin last edited 4 months ago
Evidence
Decision
Why choose Carapace over OpenClaw?
Why choose this
- Directly mitigates the January 2026 OpenClaw vulnerability classes (SSRF, plaintext secrets, unauthenticated access)
- Ed25519-signed WASM plugins with capability sandboxing vs. OpenClaw's unvetted skills supply chain
- OS-level subprocess sandboxing with fail-closed behavior on unsupported paths
Tradeoffs
- Far smaller community and ecosystem (47 stars vs. OpenClaw's scale)
- Some features are explicitly partial or in-progress per its own feature-status docs
- No comparable Control UI dashboard or Canvas-style tooling
Best fit
- Security-conscious users who want an OpenClaw-style assistant without its disclosed vulnerabilities
- Self-hosters needing multi-channel messaging (Matrix, Signal, Telegram, Discord, Slack)
- Operators who want signed, sandboxed WASM plugins instead of unvetted skills
Avoid if
- You need a large, mature plugin ecosystem and community
- You want a battle-tested project with broad third-party audits
- You prefer a simple setup over configuring hardened auth and sandboxing
Strong evidence from a detailed README, explicit security model docs, and active recent commits; however, community sentiment is essentially unmeasurable since all Reddit matches are unrelated gaming posts, so adoption signals are thin.
AI layer reviewed Sep 21, 2026 · how this is written
Star activity
47 stars today
Overview
Carapace is a security-first, Rust-based reimplementation of the OpenClaw personal AI assistant concept, explicitly positioned as a hardened alternative in the wake of the January 2026 OpenClaw security disclosures. It supports the same broad shape of functionality — multi-provider LLM access (Anthropic, OpenAI, Codex, Ollama, Gemini, Vertex, Bedrock, and more) and multi-channel messaging across Matrix, Signal, Telegram, Discord, Slack, webhooks, and console — but rebuilds the trust model from the ground up.
Its differentiators are architectural: plugins are Ed25519-signed and run in a WASM capability sandbox with resource limits; secrets live in the OS credential store with AES-256-GCM fallback; filesystem access is root-scoped and guarded; and subprocess execution uses OS-level sandboxing on macOS, Linux, and Windows with fail-closed behavior. Network posture is equally strict — localhost-only binding, CSRF-protected control endpoints, private-IP blocking, and post-resolution DNS validation to counter SSRF and rebinding attacks. Infrastructure extras include TLS/mTLS, mDNS discovery, Tailscale integration, Prometheus metrics, and audit logging.
Compared to OpenClaw, Carapace trades ecosystem breadth for assurance. It transparently documents verified-vs-partial feature status (docs/feature-status.yaml), maintains a healthy CI pipeline with ~4900 tests, fuzz targets, and active dependency hygiene, and shipped a stable v0.8.0 release in May 2026. The trade-off is a small community (47 stars) and a younger plugin ecosystem, making it best suited for security-conscious self-hosters rather than users who need OpenClaw's mature tooling and community support.