Index / ZeptoClaw · updated Oct 2, 2026
ZeptoClaw
qhkm/zeptoclaw · healthy · rank 29 of 43 by stars
A single ~6MB Rust binary that packs tools, memory, channels, 18 providers, and sandboxed autonomy into a 50ms-startup personal AI assistant. It positions itself as the synthesis of OpenClaw's integrations, NanoClaw's isolation, NemoClaw's guardrails, and PicoClaw's edge efficiency — without their tradeoffs.
Facts
Repository
Runtime
Posture
Community
Security breakdown
Composite 82 / 100 · how these are scored
higher is safer
higher is safer
higher is safer
higher is safer
higher is riskier
Model access
Read from the repository, not written by a model · 54 files examined
5 providers · gateway support
Pinned models
gpt-4o released 2024-05-13 — 2 years old (from the public model catalogue)
Pin last edited 6 months ago
Several defaults are pinned; the project picks one per provider rather than shipping a single default.
Evidence
Decision
Why choose ZeptoClaw over OpenClaw?
Why choose this
- ~6MB single Rust binary vs large TypeScript app footprint
- ~50ms startup and ~6MB RAM, viable on edge hardware
- Built-in container isolation, prompt injection detection, and circuit-breaker provider stack
Tradeoffs
- Far smaller community and ecosystem (653 stars vs OpenClaw's scale)
- No comparable skills/integrations marketplace
- CI checks were removed from GitHub Actions, relying on local validation
Best fit
- Edge and low-resource deployments (VPS, $10-class hardware)
- Users wanting OpenClaw-style integrations without the TypeScript footprint
- Local/weak-model setups needing tolerant tool-call handling
Avoid if
- You need a mature plugin/skills ecosystem like OpenClaw's
- You require enforced CI gates — the project removed GitHub Actions CI checks
- You want a large community and third-party support
Strong evidence from a detailed README, active recent commits, and a documented release; however, there is zero Reddit presence and web mentions are mostly automated ecosystem digests, so community sentiment is uncertain.
AI layer reviewed Sep 21, 2026 · how this is written
Star activity
652 stars today
Overview
ZeptoClaw is a fast, small, secure, local-first personal AI assistant infrastructure written in Rust. It ships as a single ~6MB binary that starts in ~50ms and uses ~6MB of RAM, bundling tools, long-term memory, messaging channels, 18 LLM providers, and sandboxed autonomy into one deployable unit. It explicitly positions itself as a synthesis of the Claw ecosystem: OpenClaw's integration breadth without the TypeScript footprint, NanoClaw's container isolation simplicity, NemoClaw's policy-gated guardrails without Docker/k3s overhead, and PicoClaw's edge efficiency with Rust's safety.
Architecturally, ZeptoClaw emphasizes defense-in-depth for agentic workloads: container isolation, prompt injection detection, a circuit-breaker provider stack, taint labelling, and safety scanning of model output. Recent commits show a strong focus on real-world edge deployment robustness — parsing reasoning_content from reasoning models (Qwen3, DeepSeek distills) served via Ollama/LiteLLM, sanitizing third-party MCP tool schemas so strict providers don't reject entire tool arrays, and coercing string-typed tool arguments from weak local models into their declared types. The project maintains rigorous engineering discipline with 3,900+ tests, clippy-clean code, and prompt security patching (e.g., RUSTSEC-2026-0285).
Compared to OpenClaw, ZeptoClaw trades ecosystem breadth for footprint, speed, and deploy-anywhere simplicity. One notable governance concern: the project recently removed its GitHub Actions CI checks in favor of local validation, which shifts trust onto maintainer discipline. It is best suited for individuals self-hosting a personal assistant on edge hardware or a VPS who value security controls and minimal resource usage over a large plugin marketplace.