惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Recent Announcements
Recent Announcements
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Application and Cybersecurity Blog
Application and Cybersecurity Blog
N
News | PayPal Newsroom
P
Proofpoint News Feed
L
Lohrmann on Cybersecurity
S
Security @ Cisco Blogs
K
Kaspersky official blog
A
Arctic Wolf
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Project Zero
Project Zero
L
LINUX DO - 最新话题
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
The Last Watchdog
The Last Watchdog
T
The Exploit Database - CXSecurity.com
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Security Archives - TechRepublic
Security Archives - TechRepublic
V
V2EX
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
H
Hackread – Cybersecurity News, Data Breaches, AI and More
爱范儿
爱范儿
F
Full Disclosure
I
Intezer
Schneier on Security
Schneier on Security
AWS News Blog
AWS News Blog
C
Cybersecurity and Infrastructure Security Agency CISA
博客园 - 聂微东
M
MIT News - Artificial intelligence
P
Privacy & Cybersecurity Law Blog
Attack and Defense Labs
Attack and Defense Labs
量子位
Google DeepMind News
Google DeepMind News
T
Threat Research - Cisco Blogs
Last Week in AI
Last Week in AI
Google Online Security Blog
Google Online Security Blog
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
Microsoft Security Blog
Microsoft Security Blog
Scott Helme
Scott Helme
C
Check Point Blog
N
Netflix TechBlog - Medium
博客园 - Franky
SecWiki News
SecWiki News
Know Your Adversary
Know Your Adversary
Engineering at Meta
Engineering at Meta
F
Fortinet All Blogs
Blog — PlanetScale
Blog — PlanetScale
S
Securelist

Hacker News - Newest: "OpenClaw"

OpenClaw just launched an official app for iPhone, details here - 9to5Mac OpenClaw Launch — Deploy AI Chatbots in Seconds Self-Host OpenClaw AI Agent on VPS: Full Setup Guide GitHub - xltvy/openclaw-memgpt: OpenClaw plugin that gives agents MemGPT-style memory: tiered core/archival/recall storage, self-directed memory operations via tool calls, memory-pressure warnings, and recursive summarisation. Integrates the reference MemGPT implementation via a local sidecar service, preserving the original architecture without reimplementation. Malicious AI 23 ClawHub Plugins Squat Official Org Scopes - Manifold Security what shipping OpenClaw in production taught us — AutoClaw AgentLine — AI Phone API | Phone Numbers, Voice & SMS for AI Agents Make Your OpenClaw Agent Cheaper, and Measure It Yourself GitHub - sammysltd/OpenEmployee: Make your OpenClaw agent employable: deny-by-default governance, budgets, allowlists, approval gates, and a signed audit trail via MakerChecker. Migrate from OpenClaw | Hermes Agent StackOverflow closed my OpenClaw and paperclipAI integration q. as "irrelevant" GitHub - sausin/outpost: Removing AI agents' quiet security problem Potassium — ClawHub Plugins Pi Building Pi, Openclaw's Minimalist Coding Agent | Mario Zechner, Creator of Pi I Spent 4 Hours So You Don’t Have To: Hetzner Metal + NixOS in ~15 Minutes − Irakli's blog GitHub - snuri00/osint-mcp: Self-hosted OSINT toolkit — MCP server, AI REPL, CLI, web app & chat apps (WhatsApp/Telegram/Discord via OpenClaw). Entity, event/news & social/community intelligence. Keyless-first. What a Regex Can't Do GitHub - ai-sns/openclaw-hermes-agent-network: OpenClaw Hermes AI Agent Social Network🦞💬🦞Built on Google 3D Maps and A2A protocol, connects OpenClaw and Hermes agents worldwide in a 3D environment. Phishing for Lobsters: How We Tricked OpenClaw into Spilling Secrets GitHub - CODEANDTRUST/clawcall: Give your OpenClaw / self-hosted AI agent inbound phone calls - a Twilio-to-gateway voice bridge with working agent tools mid-call (MIT). Build a ZeroCost Web Automation Pipeline with OpenRouter, OpenClaw, and MediaUse Let OpenClaw Run Wild in Simulation, Not on Your Customers | Veris AI GitHub - gpdir16/tabyAgent: A lighter, easier alternative to OpenClaw/Hermes. Runs autonomously inside Docker and chats with you through Telegram. Ask HN: What are the biggest problems you find in OpenClaw/Hermes? Microsoft launches Scout, an OpenClaw-inspired personal assistant GitHub - openclaw/openclaw-windows-node: Windows companion suite for OpenClaw - System Tray app, Shared library, Node, and PowerToys Command Palette extension Microsoft unveils Scout, an autonomous AI agent built on OpenClaw Gavriel Cohen found his own code inside OpenClaw, so he walked away GitHub - hunvreus/heypi: Chat agents for your team, with approvals and sandboxed tools. Slack, Discord, Telegram, webhooks. HolaClaw: run OpenClaw securely in Mac Multi-Agent Orchestration System: Hermes (Windows) ↔ OpenClaw (WSL) We were building infra for OpenClaw, and today I just tried Hermes and holy shit GitHub - openclaw/openclaw: Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞 OpenClaw as the Universal Operating System for Agents ARC Prize - Community Leaderboard Setup OpenClaw with Slack: from install to first message twitter.com I Gave My OpenClaw Agent a Physical Body Use Grok in OpenClaw The creator of OpenClaw used $1,300,000+ of OpenAI tokens in 30 days, which is a hell of a perk GitHub - oswarld/openshears: 🔪 THE OPENCLAW TERMINATOR 🦞 Are we human? Show HN: OpenClaw is just not dangerous enough. I needed something else OpenClaw creator burned through $1.3 million in OpenAI API tokens in a single month — bill covered 603 billion tokens across 7.6 million requests and 100 coding agents Reducing OpenClaw token usage OpenClaw/Hermes Hosting Comparison GitHub - ExTV/rikkahub-agent: RikkaHub Agent -- is RikkaHub fork that have Full agent mode . For $1.3 million a month, OpenClaw founder Peter Steinberger runs 100 AI agents that code, review PRs, and find bugs Where OpenClaw Security Is Heading OpenAI Models in OpenClaw, Done Right GitHub - thesysdev/openclaw-os: The default workspace for OpenClaw Token, Harness, OpenClaw, RAG, MCP, Agent – What's the Difference? We need a safe alternative to Telegram for agents like OpenClaw or Hermes Two OpenClaw agents negotiate a YC SAFE with Agentic Power of Attorney OpenClaw Had a Rough Week GitHub - LobsterTrap/tank-os GitHub - haishmg/Clawback How OpenClaw Got Safer in Public openclaw ggsql — ClawHub Show HN: iClaw is part OpenClaw, part Siri, powered by Apple Intelligence GitHub - lotsoftick/openclaw_client: OpenClaw web client Show HN: OpenClaw but Efficient and with an SDK GitHub - TheGuyWithoutH/mac-computer-use GitHub - microsoft/openclaw: Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞 The OpenClaw turkey problem OpenClaw: opioids for Chinese AI companies GitHub - supersuit-tech/permission-slip [AINews] The Two Sides of OpenClaw OpenClaw stats don't add up GitHub - brexhq/CrabTrap: An LLM-as-a-judge HTTP proxy to secure agents in production Anthropic - OpenClaw Hustlers are cashing in on China’s OpenClaw AI craze Engineering Managers are going to hate OpenClaw GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw Ask HN: Who is using OpenClaw? Why Meta’s AI Alignment Director Couldn't Stop Her Own Agent—and How to Fix It GitHub - epsilla-cloud/clawtrace: Make your OpenClaw agents better, cheaper, and faster. Ask HN: What are you using OpenClaw or agents for? GitHub - epsilla-cloud/clawtrace: Make your OpenClaw agents better, cheaper, and faster. GitHub - ibrahimmukherjee-boop/ClearFrame: OpenClaw Alternative with better governance, security Show HN: Agent-Notifications – Real-Time Alerts for OpenClaw and Hermes Agents OpenClaw + Claude are better than therapy GitHub - zeulewan/glueclaw: Use Claude Max subscription with OpenClaw again Anthropic temporarily banned OpenClaw’s creator from accessing Claude OpenClaw’s memory is unreliable, and you don’t know when it will break Give Your OpenClaw Agent a Real Memory You need a Windows Remote Desktop, not an OpenClaw GitHub - cruxdigital-llc/CongaLine: Deploy and manage a fleet of OpenClaw AI assistants anywhere. Supporting hobbyist, team, and enterprise use cases. GitHub - cezarpena/vsm-cell: VSM-Cell is an OpenClaw agent P2P mesh orchestration standalone app. GitHub - joshchoi4881/dropspace-agents GitHub - askalf/dario: Universal LLM router. One local endpoint, every provider — OpenAI, Groq, OpenRouter, Ollama, Claude Max/Pro subscriptions, the Claude Agent SDK, any OpenAI-compat URL. Your tools stop caring which vendor is upstream. Tutorial: Secure OpenClaw with CloudConnexa OpenClaw and the Dream of Free Labour GitHub - RageDotNet/openclaw-webdav GitHub - kevinslin/openai-apps: Support openai apps in openclaw GitHub - aelaguiz/doctrine: Code-like DSL and compiler for agent workflows that compile to portable AGENTS.md instructions. Unlocking cloud inference compute for OpenClaw OpenClaw for Sales: How AI Agents are Revolutionizing Revenue Teams | Kickscale OpenClaw Architecture - Part 1: Control Plane, Sessions, and the Event Loop
GitHub - theprint/nfh-self-improvement-loop: Minimal adversarial framework for AI agent self-modification. Inspired by karpathy/autoresearch.
2026-04-14 · via Hacker News - Newest: "OpenClaw"

An adversarial framework for AI agent self-modification, built and battle-tested in production. Inspired by karpathy/autoresearch.

The Idea

Give an AI agent the ability to modify its own codebase, then use a separate agent to decide if the change is actually good. Keep it, or throw it away. Repeat.

The hardest part isn't the implementation — it's the discipline of separation. The same agent must never build and judge its own work.

How It Works

NFH Loop Architecture

Pre-flight Checks

Before any cycle runs, a set of mandatory checks must pass:

  • Timer and duration are set (prevents runaway loops)
  • A fresh dev branch exists with no stale commits
  • state.json exists for tracking
  • Generator and evaluator prompts exist
  • Agent verification script is present and executable

Generator

The generator is a context-aware agent. Before building anything, it reads the existing workspace to find real opportunities:

  • TOOLS.md — what tools and services exist, what's available to combine
  • Learnings.md — documented friction points, known failures, past mistakes to avoid repeating (maintained by the Reflect skill)
  • USER.md — user preferences, working style, current priorities and context
  • MEMORY.md — current situation, active projects, what matters right now
  • projects/tasks/ — existing task backlog, anything aging or blocked
  • skills/ — installed skills, any combinable or underused capabilities

It then proposes and builds one improvement per cycle from three categories:

Category Focus Example
New Capabilities Build things that don't exist yet New scripts, integrations, skills, workflows
Optimization Make what exists work better Bug fixes, error handling, reduced friction, dead code cleanup
Discovery Find new ways to use what's already there Surface underused tools, find integration gaps, document opportunities

The generator's rationale — why it chose this improvement, what problem it solves, why it's valuable — is intentionally not shared with the evaluator. The code change must stand on its own merits.

Constraints:

  • One improvement per cycle
  • No edits to identity or memory files (MEMORY.md, USER.md, SOUL.md)
  • No external API calls or messages
  • Never pushes to main directly
  • No feedback from evaluator — next cycle starts fresh

Evaluator

The evaluator is a separate agent/model with a different job entirely. Where the generator asks "what would be valuable to build?", the evaluator asks "is this change actually good?"

It receives:

  • The git diff (what changed)
  • Access to the existing codebase (TOOLS.md, AGENTS.md, Learnings.md, skills/, etc.)
  • The ability to search both main and dev branches for duplicates

It does not receive:

  • The generator's rationale or proposal text
  • Any "why this is good" framing
  • The generator's context about user priorities or preferences (USER.md, MEMORY.md)

This asymmetry is deliberate. The generator's context (user preferences, priorities, emotional state) is useful for choosing what to build. But the evaluator needs to judge the code objectively — does it actually work? Is it redundant? Does it break anything? Knowing "the user really wanted this" would bias the evaluation toward approval.

The evaluator checks for:

  • Duplicate functionality on any branch
  • Use of services/skills not confirmed as configured
  • Incomplete or speculative changes
  • Over-engineered solutions for unclear benefit
  • Conflicts with existing code

Decision: APPROVE (merge to main) or REJECT (rollback dev branch). Default mindset: reject unless proven valuable.

Hard Blocks (Non-Negotiable Enforcement)

Two enforcement scripts run before any merge can happen:

verify-agents.sh — Ensures generator and evaluator are different sessions:

  • Reads generator_session_id and evaluator_session_id from state.json
  • Aborts if either is missing or if they match
  • This is the cardinal rule: same agent for generation and evaluation = theater

hard-blocks.sh — Enforces three additional invariants:

  1. Single change limit — If more than 3 files changed in a cycle, it's a batch operation. Batch operations are forbidden. Auto-rollback to main.
  2. Separate agents — Generator and evaluator session IDs must exist in state.json and must differ.
  3. Verdict recordedlast_verdict must be APPROVE before any merge. No verdict = evaluation never ran.

These scripts are called by orchestrate.sh and exit with code 1 on any violation. The loop stops immediately. These are not suggestions enforced by prompts — they are bash scripts that cannot be talked around.

Why Two Scripts?

verify-agents.sh was the original guardrail. After a production failure where a single sub-agent bypassed all evaluation (see Lessons Learned #8), hard-blocks.sh was added to enforce additional invariants that the original architecture didn't cover:

  • Batch detection (the failure mode: a sub-agent made 10 changes in one session with zero evaluation)
  • Verdict verification (ensuring evaluation actually happened before merge)

Together they form a defense-in-depth approach.

Why This Architecture

The original implementation used the same agent for both generation and evaluation. The results were predictable:

  • 82% approval rate — not a sign of quality, but of failure
  • Vague "looks good" evaluations with no real scrutiny
  • Self-congratulatory noise that wasted compute and produced zero value

After multiple failed runs, the architecture was rebuilt with enforced separation:

  1. Separate agents via isolated sessions with different models
  2. Different context for different roles — generator gets user context to choose wisely; evaluator gets codebase context to judge objectively
  3. Hard guardrails — verification scripts that abort on same-session violations
  4. State tracking — every cycle is logged with mode, decision, and approval rate
  5. Mode rotation — cycles rotate through refactor, discover, and combine to prevent the generator from fixating on one category

Inspiration

Directly inspired by karpathy/autoresearch, where an AI agent modifies training code, runs experiments, and keeps or discards based on results. The core insight is the same: let the agent iterate, but gate every change behind real scrutiny.

Where this differs: autoresearch evaluates against a training metric (loss). This loop evaluates against a separate AI agent's judgment of code quality and redundancy, making it applicable to any codebase — not just ML training runs.

Usage

Prerequisites

  • OpenClaw — for spawning isolated sub-agent sessions
  • Git — branch-based isolation

Quick Start

chmod +x nfh.sh orchestrate.sh preflight.sh verify-agents.sh hard-blocks.sh
./nfh

That's it — runs a 15-minute loop with default settings. Customize with arguments:

./nfh time=7200            # 2-hour run
./nfh cycles=10            # Exactly 10 cycles
./nfh cycles=12 time=7200  # 12 cycles or 2 hours, whichever comes first

Arguments

Argument Default Description
time=N 900 (15 min) Run duration in seconds
cycles=N 0 (unlimited) Maximum cycles to run. Stops at N regardless of time

Model Configuration

Edit generator-prompt.md and evaluator-prompt.md to reference your preferred models. The generator and evaluator should use different models for the best adversarial dynamic.

Project Structure

self-improvement/
├── nfh.sh                # Quick-launch wrapper
├── orchestrate.sh          # Main loop controller
├── preflight.sh            # Mandatory checks before any cycle
├── verify-agents.sh        # Hard guardrail: enforces separate sessions
├── hard-blocks.sh          # Hard guardrail: batch detection, verdict verification
├── generator-prompt.md     # Instructions for the generator agent
├── evaluator-prompt.md     # Instructions for the evaluator agent
├── proposal-template.md    # Template for improvement proposals
├── PLAN.md                 # Architecture documentation
├── state.json              # Run tracking, cycle stats, session IDs
└── proposals/              # Completed proposals for review

Lessons Learned

  1. Same agent = no evaluation. If generator and evaluator share a session, the entire process is theater. This is the cardinal rule.
  2. 82% approval = evaluator failure. A healthy rejection rate should be significant. Default to REJECT.
  3. Context for evaluator ≠ generator context. The generator needs user context (preferences, priorities) to choose what to build. The evaluator needs codebase context (what exists, what's redundant, behavioral rules in AGENTS.md) to judge quality. Giving the evaluator the generator's rationale biases it toward approval.
  4. Document the architecture, then enforce it in code. A PLAN.md that says "use separate agents" while the code uses the same session is a bug. Verification scripts beat documentation.
  5. Guardrails over instructions. Hard constraints (separate sessions, abort on violation) are more reliable than prompts telling the agent to behave.
  6. Prompts are not guardrails. In production, a sub-agent was spawned with a text description of the loop architecture. It ignored every instruction — batched 10 changes, never spawned a separate evaluator, never ran any verification script, and merged everything with 100% approval. The fix was adding hard-blocks.sh — a script that exits 1 (non-negotiable) on violation. Every architectural rule must have a corresponding script that can't be talked around.
  7. Track everything. State JSON with session IDs, approval rates, and mode rotation catches patterns (like approval rate creep) before they become systemic.
  8. Mode rotation prevents fixation. Without it, the generator will propose the same type of improvement repeatedly.

License

MIT


Built with OpenClaw. Inspired by karpathy/autoresearch.