Index / Moltis · updated Oct 2, 2026

Moltis

moltis-org/moltis · healthy · rank 19 of 43 by stars

A security-first personal agent server written as a single Rust binary, with sandboxed execution and no Node.js runtime. It positions itself as the hardened, auditable alternative to OpenClaw with built-in voice, memory, and multi-channel messaging.

#rust#sandboxed#self-hosted#personal-agent#security-first
Compare vs OpenClaw
GitHub ↗

Facts

Repository

Contributors70
Open issues102
Last commitSep 22, 2026
Release cadence~3 days
Latest release20260913.02

Runtime

LanguageRust
Memory15 MB
Boot time35 ms
Deploymentself-hosted · edge · desktop
Setup difficultyLow
Plugin ecosystemLimited

Posture

LicenseMIT
Local-firstYes
Cloud dependencyOptional
Multi-userNo
Privacy postureStrong

Community

Sentiment55% positive
Reddit mentions3
Web results10

Security breakdown

Composite 92 / 100 · how these are scored

Sandboxing9 / 10

higher is safer

API security8 / 10

higher is safer

Network isolation8 / 10

higher is safer

Telemetry safety9 / 10

higher is safer

Shell access risk3 / 10

higher is riskier

Model access

Read from the repository, not written by a model · 175 files examined

6 providers · runs locally · custom endpoint

Direct
AnthropicGoogleGroqMistralMoonshotOpenAI
Local
llama.cppOllama
Compatible
OpenAI-compatible

Pinned models

gpt-4oOpenAI

gpt-4o released 2024-05-13 — 2 years old (from the public model catalogue)

Pin last edited 39 days ago

Evidence

Decision

Why choose Moltis over OpenClaw?

Why choose this

  • Sandboxed container execution for every command by default
  • Single Rust binary with no Node.js/npm supply-chain exposure
  • Smaller auditable core (~7.5K lines for agent runner and model interface)

Tradeoffs

  • No plugin marketplace; extensibility limited to MCP servers
  • Smaller community and slower PR review velocity per ecosystem digests
  • Pre-1.0 with date-based versioning; API stability not guaranteed

Best fit

  • Security-conscious users wanting sandboxed agent execution
  • Self-hosters on low-power hardware like Raspberry Pi or Mac Mini
  • Users who want a single auditable Rust binary with no npm supply chain

Avoid if

  • You need a large plugin marketplace or extension ecosystem
  • You want a mature multi-user or team-oriented platform
  • You prefer TypeScript/Python stacks for easy customization
Good Confidence72%

Strong evidence from a detailed README, active releases, and CI badges; however, Reddit matches are irrelevant (Italian word 'molti') and web sentiment comes mostly from automated ecosystem digests, so community sentiment is uncertain.

AI layer reviewed Sep 21, 2026 · how this is written

Star activity

2,881 stars today

Overview

Moltis is a security-first personal agent server written entirely in Rust, distributed as a single binary with no Node.js or npm runtime dependency. Its core design principle is that every command the agent runs executes inside a sandboxed container rather than on the host, and API keys never leave the user's machine. The workspace spans ~270K lines across 59 modular crates, but the critical agent runner and model interface are kept to roughly 7.5K auditable lines, with unsafe code isolated to FFI boundaries.

Feature-wise it is surprisingly complete: multi-provider LLM support, voice, persistent memory with cross-session recall, automatic edit checkpoints, scheduling, and integrations for Telegram, Signal, WhatsApp, Discord, and Teams, plus MCP tool servers, browser automation, and SSH/node-backed remote execution. It deliberately avoids a plugin marketplace to eliminate supply-chain attack surface, relying instead on built-in capabilities and MCP.

Compared to OpenClaw's TypeScript stack with companion mobile apps, Moltis trades ecosystem breadth for hardening and auditability. It runs comfortably on a Raspberry Pi or Mac Mini, making it a strong fit for privacy-focused self-hosters, though its smaller community and pre-1.0 status mean slower PR review and less extension variety than OpenClaw.

Nominate a clone

Add a new Claw

Paste a GitHub repository and tell us why it belongs on the tracker.

Opens a prefilled issue on GitHub — every nomination is public. Comfortable with a PR? Adding the repo to projects.json is faster.