Index / Moltis · updated Oct 2, 2026
Moltis
moltis-org/moltis · healthy · rank 19 of 43 by stars
A security-first personal agent server written as a single Rust binary, with sandboxed execution and no Node.js runtime. It positions itself as the hardened, auditable alternative to OpenClaw with built-in voice, memory, and multi-channel messaging.
Facts
Repository
Runtime
Posture
Community
Security breakdown
Composite 92 / 100 · how these are scored
higher is safer
higher is safer
higher is safer
higher is safer
higher is riskier
Model access
Read from the repository, not written by a model · 175 files examined
6 providers · runs locally · custom endpoint
Pinned models
gpt-4o released 2024-05-13 — 2 years old (from the public model catalogue)
Pin last edited 39 days ago
Evidence
Decision
Why choose Moltis over OpenClaw?
Why choose this
- Sandboxed container execution for every command by default
- Single Rust binary with no Node.js/npm supply-chain exposure
- Smaller auditable core (~7.5K lines for agent runner and model interface)
Tradeoffs
- No plugin marketplace; extensibility limited to MCP servers
- Smaller community and slower PR review velocity per ecosystem digests
- Pre-1.0 with date-based versioning; API stability not guaranteed
Best fit
- Security-conscious users wanting sandboxed agent execution
- Self-hosters on low-power hardware like Raspberry Pi or Mac Mini
- Users who want a single auditable Rust binary with no npm supply chain
Avoid if
- You need a large plugin marketplace or extension ecosystem
- You want a mature multi-user or team-oriented platform
- You prefer TypeScript/Python stacks for easy customization
Strong evidence from a detailed README, active releases, and CI badges; however, Reddit matches are irrelevant (Italian word 'molti') and web sentiment comes mostly from automated ecosystem digests, so community sentiment is uncertain.
AI layer reviewed Sep 21, 2026 · how this is written
Star activity
2,881 stars today
Overview
Moltis is a security-first personal agent server written entirely in Rust, distributed as a single binary with no Node.js or npm runtime dependency. Its core design principle is that every command the agent runs executes inside a sandboxed container rather than on the host, and API keys never leave the user's machine. The workspace spans ~270K lines across 59 modular crates, but the critical agent runner and model interface are kept to roughly 7.5K auditable lines, with unsafe code isolated to FFI boundaries.
Feature-wise it is surprisingly complete: multi-provider LLM support, voice, persistent memory with cross-session recall, automatic edit checkpoints, scheduling, and integrations for Telegram, Signal, WhatsApp, Discord, and Teams, plus MCP tool servers, browser automation, and SSH/node-backed remote execution. It deliberately avoids a plugin marketplace to eliminate supply-chain attack surface, relying instead on built-in capabilities and MCP.
Compared to OpenClaw's TypeScript stack with companion mobile apps, Moltis trades ecosystem breadth for hardening and auditability. It runs comfortably on a Raspberry Pi or Mac Mini, making it a strong fit for privacy-focused self-hosters, though its smaller community and pre-1.0 status mean slower PR review and less extension variety than OpenClaw.