Index / Carapace · updated Oct 2, 2026

Carapace

puremachinery/carapace · healthy · rank 39 of 43 by stars

A security-hardened Rust rewrite of the OpenClaw personal assistant concept, built explicitly to counter the January 2026 OpenClaw vulnerability disclosures. It pairs a signed WASM plugin runtime with OS-level sandboxing and encrypted secret storage for a genuinely locked-down local agent.

#rust#security-hardened#local-first#wasm-plugins#multi-channel
Compare vs OpenClaw
GitHub ↗

Facts

Repository

Contributors5
Open issues16
Last commitSep 29, 2026
Release cadence~7 days
Latest releasev0.8.0

Runtime

LanguageRust
Memory15 MB
Boot time35 ms
Deploymentself-hosted · desktop · cloud
Setup difficultyMedium
Plugin ecosystemEmerging

Posture

LicenseApache-2.0
Local-firstYes
Cloud dependencyOptional
Privacy postureStrong

Community

Sentiment35% positive
Reddit mentions17
Web results10

Security breakdown

Composite 92 / 100 · how these are scored

Sandboxing9 / 10

higher is safer

API security9 / 10

higher is safer

Network isolation9 / 10

higher is safer

Telemetry safety8 / 10

higher is safer

Shell access risk3 / 10

higher is riskier

Model access

Read from the repository, not written by a model · 46 files examined

5 providers · runs locally · custom endpoint

Direct
AnthropicAWS BedrockGoogleOpenAIVertex AI
Local
OllamavLLM
Compatible
OpenAI-compatible

Pinned models

gpt-5.5OpenAI

gpt-5.5 released 2026-04-24 — 5 months old (from the public model catalogue)

Pin last edited 4 months ago

Evidence

Decision

Why choose Carapace over OpenClaw?

Why choose this

  • Directly mitigates the January 2026 OpenClaw vulnerability classes (SSRF, plaintext secrets, unauthenticated access)
  • Ed25519-signed WASM plugins with capability sandboxing vs. OpenClaw's unvetted skills supply chain
  • OS-level subprocess sandboxing with fail-closed behavior on unsupported paths

Tradeoffs

  • Far smaller community and ecosystem (47 stars vs. OpenClaw's scale)
  • Some features are explicitly partial or in-progress per its own feature-status docs
  • No comparable Control UI dashboard or Canvas-style tooling

Best fit

  • Security-conscious users who want an OpenClaw-style assistant without its disclosed vulnerabilities
  • Self-hosters needing multi-channel messaging (Matrix, Signal, Telegram, Discord, Slack)
  • Operators who want signed, sandboxed WASM plugins instead of unvetted skills

Avoid if

  • You need a large, mature plugin ecosystem and community
  • You want a battle-tested project with broad third-party audits
  • You prefer a simple setup over configuring hardened auth and sandboxing
Good Confidence78%

Strong evidence from a detailed README, explicit security model docs, and active recent commits; however, community sentiment is essentially unmeasurable since all Reddit matches are unrelated gaming posts, so adoption signals are thin.

AI layer reviewed Sep 21, 2026 · how this is written

Star activity

47 stars today

Overview

Carapace is a security-first, Rust-based reimplementation of the OpenClaw personal AI assistant concept, explicitly positioned as a hardened alternative in the wake of the January 2026 OpenClaw security disclosures. It supports the same broad shape of functionality — multi-provider LLM access (Anthropic, OpenAI, Codex, Ollama, Gemini, Vertex, Bedrock, and more) and multi-channel messaging across Matrix, Signal, Telegram, Discord, Slack, webhooks, and console — but rebuilds the trust model from the ground up.

Its differentiators are architectural: plugins are Ed25519-signed and run in a WASM capability sandbox with resource limits; secrets live in the OS credential store with AES-256-GCM fallback; filesystem access is root-scoped and guarded; and subprocess execution uses OS-level sandboxing on macOS, Linux, and Windows with fail-closed behavior. Network posture is equally strict — localhost-only binding, CSRF-protected control endpoints, private-IP blocking, and post-resolution DNS validation to counter SSRF and rebinding attacks. Infrastructure extras include TLS/mTLS, mDNS discovery, Tailscale integration, Prometheus metrics, and audit logging.

Compared to OpenClaw, Carapace trades ecosystem breadth for assurance. It transparently documents verified-vs-partial feature status (docs/feature-status.yaml), maintains a healthy CI pipeline with ~4900 tests, fuzz targets, and active dependency hygiene, and shipped a stable v0.8.0 release in May 2026. The trade-off is a small community (47 stars) and a younger plugin ecosystem, making it best suited for security-conscious self-hosters rather than users who need OpenClaw's mature tooling and community support.

Nominate a clone

Add a new Claw

Paste a GitHub repository and tell us why it belongs on the tracker.

Opens a prefilled issue on GitHub — every nomination is public. Comfortable with a PR? Adding the repo to projects.json is faster.