OpenClaw is the AI agent everyone is suddenly messaging on WhatsApp — an open-source assistant that runs on a computer you control, connects to a model like Claude, GPT or Gemini, and then does real tasks for you around the clock. If you have seen the GitHub stars or the viral X exchange with Google’s CEO and wondered whether to try it or avoid it, this review gives you the working answer: what it is, how it runs, what it costs, and the safety setup that decides whether it helps or hurts.
What is OpenClaw, in plain terms?
OpenClaw is a self-hosted AI agent with hands, not just a chatbot. You message it in WhatsApp, Telegram, Slack, Discord, Signal or iMessage, and it can read files, run commands, browse the web and call apps on your behalf while you are away. ChatGPT and Claude advise; OpenClaw is built to do the thing and report back in the same chat thread.
The project was started by Austrian developer Peter Steinberger in November 2025 (Storyboard18, 4 October 2026). Within nine months it grew to a 10-person team, and its GitHub repository crossed 387,000 stars and 81,000 forks (Storyboard18, 4 October 2026). A second October 2026 guide puts the count at about 390,000 stars, with a 1 October milestone of 390,000 stars and 82,100 forks (JarvisReach OpenClaw guide, October 2026) — treat the total as fast-moving. Steinberger joined OpenAI in February 2026, and the project moved under the independent OpenClaw Foundation, a 501(c)(3) nonprofit, while the code stays MIT open source (JarvisReach, October 2026). He was also named to Time’s Most Influential People in AI list in August 2026 (Storyboard18, 4 October 2026).
Think of ChatGPT as an advisor. It tells you how to do something. Think of OpenClaw as a helper with hands. It actually does the thing for you.
— JarvisReach OpenClaw guide, October 2026
Why did OpenClaw go viral again in October 2026?
A stalled app review became a CEO-level support ticket on X — and it worked. Steinberger posted publicly after OpenClaw’s Android app sat in Google review for more than a week, asking if anyone had a contact who could help. Google CEO Sundar Pichai replied directly:
@steipete Ack, will follow up
— Sundar Pichai (@sundarpichai), 3 October 2026 (via Storyboard18)
Storyboard18 (4 October 2026) reports that reply drew about 2.1 million views and 10,000 likes, after which Steinberger confirmed the update was live. OpenClaw’s companion app launched for iPhone and Android on 29 June 2026 and pairs by QR code to your own Gateway rather than running the AI on the phone (JarvisReach, October 2026). OpenClaw also ranked #4 in a 1 October 2026 roundup of the Top 10 Trending AI GitHub Repos, which is why “how do I run this safely?” is now the search, not just “what is it?”. Before any agent touches email or files, run the audit in our AI Agent Permissions Guide.
How does OpenClaw actually work?
OpenClaw is a switchboard between your chat apps and an AI model, plus memory and tools on your machine. Everything except the model runs in one program — the Gateway, a Node.js service on port 18789 by default, with a web dashboard (the Control UI) where you chat, watch work and approve risky actions (JarvisReach, October 2026, citing OpenClaw docs).
When you text “Summarise my unread email”, the Gateway loads SOUL.md (personality) and AGENTS.md (role and rules) plus memory notes, sends that context to your model, runs any tool the model requests — for example Gmail through a skill — and loops until the task is done. Replies land back in your chat app, and important context is saved to plain-text memory files on your disk that you can read and edit.
Two pieces make it feel different. The heartbeat wakes the agent every 30 minutes by default to check a to-do list and only messages you if something needs attention (JarvisReach, October 2026) — that is how a 7 a.m. briefing with meetings, weather and urgent email happens unprompted. Skills are folders with a SKILL.md file in plain language that teach the agent an app. ClawHub, the public marketplace, listed more than 10,700 skills as of July 2026 (ClawDocs via JarvisReach, October 2026). Models are bring-your-own — Claude, GPT, Gemini or a local model through Ollama — so cost and safety depend on what you connect.
OpenClaw vs ChatGPT vs Claude: which should you use?
Use ChatGPT or Claude for instant answers with zero setup; use OpenClaw when work should continue after you close the app. Many people run both. The table follows JarvisReach (October 2026); ChatGPT Plus and Claude Pro are $20/month from Mastra’s July 2026 review (via JarvisReach).
| Feature | OpenClaw | ChatGPT | Claude |
|---|---|---|---|
| Type | Self-hosted AI agent | Chat assistant by OpenAI | Chat assistant by Anthropic |
| Where it runs | Your computer or server | OpenAI’s cloud | Anthropic’s cloud |
| Talk via | WhatsApp, Telegram, Slack, Discord, Signal, iMessage | ChatGPT app or website | Claude app or website |
| Works on a schedule | Yes — every 30 minutes by default | Limited | Limited |
| Memory | Plain files on your disk | Saved in your OpenAI account | Saved in your Anthropic account |
| Models | Any (Claude, GPT, Gemini, local) | OpenAI only | Anthropic only |
| Price | Free software; you pay AI use + hosting | Free; Plus $20/month | Free; Pro $20/month |
| Who handles safety | You do | OpenAI | Anthropic |
Claude Cowork, which runs in an isolated virtual machine, is the closest hosted match if you want safety out of the box (CNET via JarvisReach, October 2026). For how fast the wider tooling moves, see AI Tools October 2026: Kolibri, Gemini Skills & More.
What does OpenClaw really cost?
The software is $0; running it is not. OpenClaw is free under MIT with no paid tier, but you pay for the AI model and the machine it runs on (JarvisReach, October 2026). A light setup is about $5–$25/month; heavy use costs hundreds.
| Setup | Hosting / month | AI use / month | Total / month |
|---|---|---|---|
| Light, computer you own | About $0 | $5–$20 | $5–$20 |
| Light, budget cloud server | About $5 | $5–$20 | $10–$25 |
| Active daily assistant | $5–$24 | $50–$150 | $55–$174 |
| Heavy, top models | $5–$24+ | $270–$540+ | $275–$564+ |
| Local model via Ollama | $0 | $0 | $0 (needs strong hardware) |
Ranges from Milvus usage reports via JarvisReach (October 2026). The $24 figure is DigitalOcean’s one-click OpenClaw server starting price (via JarvisReach). Every step sends instructions, history, tools and memory to the model, and the heartbeat adds calls when idle — Milvus reports untuned power users received bills in the thousands (via JarvisReach). You do not need a Mac mini: the official minimum is 2 GB RAM and 2 CPU cores, 4 GB for browser automation (official install guide v2026.9.7 via JarvisReach).
Is OpenClaw safe to run?
Only as safe as your setup — out of the box it carries real risk, and this is the review’s key caveat. Microsoft’s security team said in February 2026 that OpenClaw “should be treated as untrusted code execution with persistent credentials” and is not appropriate for a standard personal or work computer (Microsoft Security Blog via JarvisReach, October 2026). The Register’s 31 August 2026 review of OpenClaw 2.0 (via JarvisReach) found saved passwords and API keys are not encrypted at rest and the sandbox is still off by default. China’s vulnerability database logged 237 OpenClaw flaws between January and early April 2026, with fast patches that require you to update just as fast (CNNVD via JarvisReach).
- It holds the keys. Stored login tokens mean anyone who hijacks the agent gets them too.
- Hidden instructions steer it. Prompt injection hides orders in email or web pages the agent reads.
- Skills can carry malware. Koi Security exposed ClawHavoc with 341 malicious skills in February 2026; Bitdefender found about 17% of early checked skills carried malware (via JarvisReach, October 2026).
- It can misread you at speed. On 23 February 2026 an agent mass-deleted an inbox after being told to confirm first (via JarvisReach).
Do not skip this checklist: run it on a separate machine, VM or cheap cloud server; give it its own email and scoped API keys with a hard spend limit; keep port 18789 private (never expose it; use Tailscale or local binding); turn the sandbox on; require approval for payments, deletions and outbound email; update weekly; read every SKILL.md and refuse skills that ask for a Terminal paste or a password-protected ZIP — the ClawHavoc trick. This review is desk-validated, not a hands-on install test.
How do you install OpenClaw, step by step?
Install takes about 15 minutes; hardening takes longer and matters more. Steps follow the official install guide v2026.9.7 (via JarvisReach, October 2026). OpenClaw 2.0 (v2026.8.1, 30 August 2026) shipped 16,977 pull requests and 987 contributors in the official notes (via JarvisReach); the latest line is v2026.9.7 as of 1 October 2026. You need a machine with 2 GB RAM (4 GB for browser automation), an API key or Ollama, and fresh agent-only accounts created beforehand.
- Run the installer. Mac/Linux/WSL2:
curl -fsSL https://openclaw.ai/install.sh | bash. Windows PowerShell:iwr -useb https://openclaw.ai/install.ps1 | iex. Download only from openclaw.ai or official GitHub — fake installers use old names like Clawdbot. - Finish the wizard. Pick your provider, paste your API key, set up the Gateway, link a first chat app, install the background service. Re-run with
openclaw onboard --install-daemon. - Verify. Run
openclaw --version,openclaw doctor, thenopenclaw gateway status. - Open the dashboard. Run
openclaw dashboard(local port 18789) and test there before connecting any chat app. - Connect a chat app. Run
openclaw configure --section channels. For Telegram, create a bot via BotFather, paste the token, then try “What is on my calendar today?” - Lock down first. Keep the Gateway private, enable the sandbox, run
openclaw security audit. Only then connect email or personal accounts.
Easier paths: DigitalOcean’s hardened one-click server from $24/month; ollama launch openclaw with Ollama 0.17+ (needs about 25 GB graphics memory for local models); or 15+ managed hosts (all via JarvisReach, October 2026). Start with a morning briefing and inbox triage with drafts-for-approval — it proves the heartbeat without giving send or delete power on day one.
Should you try OpenClaw? Our try-first framework
Try OpenClaw only if you pass all five checks; otherwise start hosted and revisit in a quarter. This desk-validated framework — the original element of this review, not a hands-on benchmark — is built to stop the two common mistakes: installing on a daily-driver laptop, and wiring a main inbox before a sandbox exists.
- Separate home? Spare machine, VM or $5–$24/month server with no sensitive data? If no, use Claude Cowork or ChatGPT.
- Terminal comfort? Can you run the verify commands and read a SKILL.md? If no, choose a managed host.
- Key hygiene? Fresh email, scoped keys, hard spend limit set first? If no, test dashboard-only.
- Skill discipline? Built-ins first, read every SKILL.md, refuse Terminal-paste skills? If no, ClawHub’s malware history is your risk.
- Approval habit? Approvals for money/deletes/sends, private Gateway, sandbox on, weekly updates? Score: 5/5 try it this week; 3–4/5 dashboard-only; 0–2/5 stay hosted.
When you add writable skills, apply the same audit-first mindset as our Gemini Skills Guide — narrow, stackable skills beat one broad agent. Bottom line: OpenClaw makes the trade-off explicit — your server, your keys, your rules, your risk. That is thrilling if you are set up for it, and a fast way to delete an inbox if you are not.
Frequently asked questions
Is OpenClaw free?
The software is free under MIT. Running it is not: light use is about $5–$25/month, an active assistant $55–$174/month, heavy use $275–$564+/month (Milvus via JarvisReach, October 2026). A local Ollama model can be $0 if you own hardware with about 25 GB graphics memory.
Is OpenClaw safe for beginners?
Not yet for most beginners. Microsoft (February 2026, via JarvisReach) advises against everyday computers, the sandbox is off by default (The Register, 31 August 2026, via JarvisReach), and a maintainer has warned that anyone who cannot use a command line should not run it (via JarvisReach). Start with a managed host, Claude Cowork, or dashboard-only on a separate machine.
What is the difference between OpenClaw, Clawdbot and OpenClawd?
Same lineage. Warelay (24 November 2025), CLAWDIS (3 December 2025), Clawdbot (2 January 2026), Moltbot (27 January 2026), then OpenClaw (30 January 2026) (Wikipedia via JarvisReach, October 2026). “OpenClawd” is unofficial; the official site is openclaw.ai (via JarvisReach). Download only from openclaw.ai or official GitHub.
What is new in OpenClaw 2.0?
OpenClaw 2.0 (v2026.8.1, 30 August 2026) added easier install, a rebuilt Control UI, searchable memory, a Skill Workshop, computer use on paired machines and request-bound approvals — 16,977 pull requests and 987 contributors (official notes via JarvisReach, October 2026). The sandbox is still off by default (The Register via JarvisReach), so the checklist above still applies.
Sources and methodology
This review rests on Storyboard18 (4 October 2026) for the Steinberger–Pichai exchange and project scale, and JarvisReach’s October 2026 OpenClaw guide (v2026.9.7), which synthesises the official install guide and docs, Microsoft Security Blog (February 2026), Unit 42, Koi Security, Bitdefender, Trend Micro, The Register (31 August 2026), CNET, Milvus, DigitalOcean, ClawDocs and Wikipedia. Figures are shown beside their source and date and should be re-checked on GitHub and provider dashboards before you spend or install. Where sources differ slightly (387,000 vs about 390,000 stars), both dated figures are shown. This article is desk-validated, not a hands-on install test: no instance was run, no skills executed, and costs are compiled reports, not metered bills. Verification date: 5 October 2026.
- Storyboard18: Sundar Pichai answers OpenClaw creator’s call for help on X (4 October 2026)
- JarvisReach: What Is OpenClaw? Uses, Cost and Safety Guide (October 2026)
- YouTube: Top 10 Trending AI GitHub Repos – 1 October 2026
Arva Rangwala covers AI news, AI tools, guides and prompts for OpenAIMaster — what is new, what is worth using, and how to put AI to work.
Feel free to email us at contact@openaimaster.ai — we are happy to help!


