Index / NanoClaw · updated Oct 2, 2026
NanoClaw
qwibitai/nanoclaw · healthy · rank 8 of 43 by stars
A radically minimal OpenClaw alternative that runs each agent in its own Linux container for true OS-level isolation. Small enough to read end-to-end, with first-class Slack multi-agent support and Anthropic Agents SDK under the hood.
Facts
Repository
Runtime
Posture
Community
Security breakdown
Composite 88 / 100 · how these are scored
higher is safer
higher is safer
higher is safer
higher is safer
higher is riskier
Model access
Read from the repository, not written by a model · 49 files examined
2 providers · runs locally · custom endpoint
Pinned models
None pinned in the repository.
Evidence
Decision
Why choose NanoClaw over OpenClaw?
Why choose this
- True container-level isolation instead of app-level permission checks
- Codebase small enough to fully audit and understand
- Per-agent Slack apps with automated provisioning
Tradeoffs
- Far fewer features, integrations, and config options
- Smaller ecosystem and community resources
- Requires Docker/container runtime on the host
Best fit
- Security-conscious users who want OS-level agent isolation
- Developers who want a small, auditable codebase
- Teams spawning multiple Slack agents with separate identities
Avoid if
- You need OpenClaw's full feature breadth and plugin ecosystem
- You want a mature GUI dashboard and control UI
- You cannot run Docker/containers on your host
Strong evidence from README, active recent commits, and multiple ecosystem mentions; sentiment data is mostly indirect ecosystem digests rather than deep user reviews, so community scores carry moderate uncertainty.
AI layer reviewed Sep 21, 2026 · how this is written
Star activity
30,865 stars today
Overview
NanoClaw is a deliberately minimal rethinking of OpenClaw: instead of a half-million-line monolith with application-level permission checks, it runs each agent inside its own Linux container with real filesystem isolation. The entire system is one process and a handful of files, built directly on Anthropic's Agents SDK, so a single developer can read and audit the whole codebase before trusting it with their accounts.
It connects to WhatsApp, Telegram, Slack, Discord, Gmail, iMessage, and a local CLI, with persistent memory and scheduled jobs. A standout feature is its Slack integration: setup provisions each agent its own Slack app (manifest, avatar, workspace install) with no manual token pasting, and you can spawn new teammates from chat, each with its own bot identity, container, and memory.
The nanoclaw.sh bootstrap walks a fresh machine from zero to a paired, named agent — installing Node, pnpm, and Docker, registering Anthropic credentials via OneCLI, and even invoking Claude Code to auto-diagnose failed steps. Recent commits show active maintenance focused on setup robustness (user-owned npm prefix fallbacks, corepack EACCES handling). Compared to OpenClaw, it trades feature breadth and ecosystem maturity for auditability, isolation, and operational simplicity.