惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
L
LangChain Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
云风的 BLOG
云风的 BLOG
月光博客
月光博客
F
Full Disclosure
G
Google Developers Blog
MongoDB | Blog
MongoDB | Blog
T
Tailwind CSS Blog
F
Fortinet All Blogs
A
About on SuperTechFans
Stack Overflow Blog
Stack Overflow Blog
J
Java Code Geeks
Microsoft Azure Blog
Microsoft Azure Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Recorded Future
Recorded Future
Y
Y Combinator Blog
博客园 - 聂微东
爱范儿
爱范儿
D
DataBreaches.Net
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Threat Research - Cisco Blogs
L
Lohrmann on Cybersecurity
The Hacker News
The Hacker News
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Scott Helme
Scott Helme
L
LINUX DO - 热门话题
Apple Machine Learning Research
Apple Machine Learning Research
C
CERT Recently Published Vulnerability Notes
B
Blog RSS Feed
The Last Watchdog
The Last Watchdog
SecWiki News
SecWiki News
Webroot Blog
Webroot Blog
Engineering at Meta
Engineering at Meta
T
Tenable Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
O
OpenAI News
Google DeepMind News
Google DeepMind News
Security Archives - TechRepublic
Security Archives - TechRepublic
W
WeLiveSecurity
Hacker News: Ask HN
Hacker News: Ask HN
Hacker News - Newest:
Hacker News - Newest: "LLM"
T
Troy Hunt's Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
aimingoo的专栏
aimingoo的专栏
GbyAI
GbyAI
V
Vulnerabilities – Threatpost
N
News and Events Feed by Topic

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Top 10 Local AI Agents You Can Run on Your PC in 2026
rednakta · 2026-05-06 · via DEV Community

A practical comparison of every personal AI agent worth installing in 2026 — and one underneath layer that simplifies running them.


OpenClaw Cleared 345k Stars in 8 Weeks. Then the Ecosystem Showed Up.

No open-source project has ever crossed 345,000 stars that fast. OpenClaw cleared a decade of React's record like it wasn't there. And almost as fast as the original landed, an entire *Claw ecosystem grew underneath it: NanoClaw, Hermes Agent, Nanobot, ZeroClaw, NullClaw, IronClaw, PicoClaw, Moltworker. A dozen variations on the same idea, all painting the same picture at once. A personal AI agent that lives on your laptop, talks to a local model, and actually gets things done.

If you're picking one in 2026, "is local AI ready?" isn't the question anymore. The real one is:

Which of these do I install, and where do I run it so it doesn't eat my home directory?

That's the post.


Why This Category Exploded in 2026

Three things happened at once.

  1. Local models stopped being toys. Qwen 3, Gemma 4, Llama 4, the Hermes 4 fine-tunes — all of them run usefully on a Mac mini or a midrange RTX. The "send everything to OpenAI" tax stopped being mandatory.
  2. MCP arrived. Model Context Protocol gave agents a standard way to grow tools, and the npm/pip ecosystem rushed to fill the catalog. (That a few of those entries turned out to be backdoors is its own story.)
  3. OpenClaw made it look easy. A weekend project from one Austrian developer proved you could ship a personal agent — laptop-resident, messaging-app-aware, persistently running — without a billion-dollar lab. Once that proof landed, every smaller team in the world started forking it.

The result is healthy, noisy, and slightly chaotic.


The 10 at a Glance

Agent Language Approx LoC Sandbox model One-line trait
OpenClaw TypeScript ~430,000 Application-level checks, shared process The original; broadest tool catalog
NanoClaw TypeScript ~500 (core) / ~15 files OS-level container per agent (Docker, Apple Container) Slim rewrite + real isolation
Hermes Agent Python mid 5 backends: local, Docker, SSH, Singularity, Modal Memory + skill-learning loop
Nanobot Python ~4,000 Process-level OpenClaw's core in 1% of the code
ZeroClaw Rust small Process / OS-level Single binary, 30+ channels, ~20 model providers
NullClaw Zig very small Process-level 678KB binary, 1MB RAM, sub-2ms boot
IronClaw TypeScript small WebAssembly per tool Default-zero-permission tools
PicoClaw Python very small Process-level The minimum viable variant
Moltworker TypeScript n/a Cloudflare Workers (serverless) No local install, no host access
memU Python mid n/a (library) Long-term memory layer that bolts onto any agent

1. OpenClaw — The One That Started Everything

A personal AI agent that runs on your laptop, talks to local or remote models, and exposes itself through every messaging app you already use. Started as a weekend project, hit 250k stars in 60 days, kept going.

Strengths. Biggest community, biggest skill marketplace, broadest "it just works" tool catalog. Default skills cover code, web, files, calendar, mail, and dozens of integrations.

Weaknesses. ~430k lines across hundreds of files, in a layered architecture nobody fully understands. Isolation is enforced at the application level inside a single shared process — if one skill misbehaves, it can in principle reach anything OpenClaw can reach, which is most of your machine.

Run on. Any modern machine. Resource-hungry.


2. NanoClaw — The Slim, Container-Isolated Rewrite

Take OpenClaw's idea, throw out 99.9% of the code, and run each agent inside its own Docker container instead of trusting application-level permission checks.

Strengths. ~15 source files. ~500 lines of TypeScript at the core. One Node.js process. Every agent runs under OS-level container isolation — Docker on Linux/WSL2, Docker or Apple Container on macOS. If a skill goes off the rails, the blast radius is the container, not your home directory. Built on top of Anthropic's Claude Agent SDK.

Weaknesses. Smaller skill catalog than OpenClaw, so more glue code. Docker requirement is a real ask for non-technical users.

Run on. Mac, Linux, WSL2 with Docker. Famously, also on a Raspberry Pi.


3. Hermes Agent — The One That Learns

From Nous Research, the lab behind the Hermes / Nomos / Psyche model families. Built around a do → learn → improve loop — every successful task becomes a reusable skill, every interaction updates a persistent model of the user.

Strengths. Memory across sessions that actually changes behavior, not just retrieval. Auto-detects models installed via Ollama and ships per-model tool-call parsers — so a 7B local Qwen runs predictably instead of half-broken. Five sandbox backends out of the box: local, docker, ssh, singularity, modal. 110k stars in 10 weeks.

Weaknesses. More server-shaped than desktop-shaped — the natural deployment is "leave it running on a VPS or home server, talk to it from Telegram/Discord/Slack/Signal/WhatsApp/email," not "click an icon on your dock." More moving parts at setup.

Run on. Anywhere with Python and one of the five sandbox backends. Especially good on AMD Ryzen AI Max+ and Apple Silicon.


4. Nanobot — OpenClaw's Core in 4,000 Lines

From HKUDS at Hong Kong University. Deliver OpenClaw's core capabilities — tool use, messenger integrations, memory, scheduling — in code small enough for one person to read every line in an afternoon.

Strengths. ~4,000 lines of Python. 26,800+ stars. Auditability as a feature: when something breaks, you fix it. Telegram, Discord, WhatsApp out of the box.

Weaknesses. Process-level isolation only. No built-in container boundary — you bring the sandbox.

Run on. Anywhere Python runs.


5. ZeroClaw — Rust Single-Binary

From zeroclaw-labs. One Rust binary; configure and run. Talks to 20+ LLM providers and reaches the world through 30+ channels.

Strengths. Single static binary — no runtime, no node_modules, no Python venv. Cross-compiles anywhere. The "spiritual successor to NullClaw" with a community an order of magnitude larger.

Weaknesses. Newer ecosystem; the skill marketplace is thinner. Rust learning curve if you write tools natively (MCP servers work fine as-is).

Run on. Any OS / architecture you can cargo build --target to.


6. NullClaw — The Bare-Metal Pick

Written in Zig. 678KB static binary. ~1MB RAM at idle. Boots in under 2 milliseconds on Apple Silicon.

Strengths. The agent for tight resource budgets. Routers. Edge devices. Raspberry Pi Zero. The boundary between "agent" and "embedded firmware" gets blurry — that's the point.

Weaknesses. ~2,600 stars at writing — a quarter the size of ZeroClaw's community. Sparse documentation.

Run on. Anything with a CPU. Genuinely.


7. IronClaw — WebAssembly All the Way Down

Every tool runs inside its own WebAssembly sandbox, default zero permissions. Network access, filesystem access, secret access — each explicitly granted per tool, denied otherwise. Built-in leak detection scans agent outputs to catch API keys and PII before they escape.

Strengths. The closest design in this list to capability-secure. If you've spent serious time worrying about prompt-injection-driven secret exfil, IronClaw takes that threat model seriously at the language-runtime level.

Weaknesses. WASM ecosystem still maturing for general tool use. Slower than process-level alternatives on tool-heavy workloads.

Run on. Anywhere wasmtime / wasmer runs.


8. PicoClaw — The Textbook Minimum

The smallest functional variant. If a 4,000-line codebase still feels like too much, this is the starting point.

Strengths. Educational. A great fork starting point for very specific use cases.

Weaknesses. Deliberately missing things. Don't ship as a daily driver.

Run on. Wherever you'd run a 200-line Python script.


9. Moltworker — Cloudflare-Style Serverless Variation

Cloudflare's official adaptation of the OpenClaw idea to Cloudflare Workers. The agent runs serverless inside Cloudflare's sandbox; nothing executes on your local machine.

Strengths. Zero local footprint. Scales to zero when nobody's using it. Bills per invocation.

Weaknesses. Not a local agent. If your value prop is "stays on my hardware," wrong column. If it's "give my team an OpenClaw-shaped thing without thinking about hosting," exactly right.

Run on. A Cloudflare account.


10. memU — The Memory Layer

From NevaMind AI. Strictly speaking, not an agent — a long-term memory engine that plugs into any of the agents above. Builds a local knowledge graph of your preferences, past projects, and habits.

Strengths. Pair with NanoClaw or Hermes and the agent stops re-learning who you are every session. Local-first by default.

Weaknesses. A component, not an agent. To actually do something, you still need one of the items above.

Run on. Wherever the agent you pair it with runs.


The Sandbox Question Underneath All Ten

Pick any agent above and read its security model. They fall into one of three buckets.

  • Process-level only (OpenClaw, Nanobot, PicoClaw, NullClaw default): a misbehaving skill can reach anything the agent process can reach. On your laptop, that's most of your PC.
  • Container per agent (NanoClaw, Hermes Agent in Docker mode, ZeroClaw in some configs): an OS-level boundary, much better, still shares the kernel.
  • Capability-secure (IronClaw at the tool layer): rigorous, but only IronClaw, and only for tools — the agent process itself still has capabilities.

And by default, none of them defends against the other class of attack: the agent leaking its API token. A prompt injection that gets the model to echo $OPEN_API_TOKEN. A malicious npm/pip dependency that POSTs process.env. An MCP server that quietly BCC's its operator on every call. The token is real, the agent can read it, a single successful exfil sweeps out the rest of the month's API budget at minimum.

The right shape is a VM around the entire agent plus a token-substitution boundary so the agent never sees the real key.


One nilbox Install Replaces Ten Sandbox Configurations

That's what nilbox is. One installer for macOS, Windows, Linux. Inside it, a Debian VM (Linux for nilbox) where you install OpenClaw, or Hermes, or whichever variant on this list you picked — unmodified, the same way the README tells you to. The agent runs as-is. API tokens are placeholders; the real values get swapped in only at the boundary on the way out. Network egress goes through that boundary and nowhere else. Full write-up: Zero Token Architecture.

And here's what falls out on top of security: you stop having to learn ten different sandbox models.

  • NanoClaw wants Docker.
  • Hermes wants you to pick between local, docker, ssh, singularity, and modal.
  • IronClaw wants you to think in WASM capabilities.
  • ZeroClaw runs bare and will technically work that way — until you remember it shouldn't.

Each one ships its own threat model, its own setup checklist, its own "did I configure isolation correctly?" question. Run two of them on the same machine and you're maintaining two unrelated sandbox stacks at once.

Drop them all into nilbox and that whole layer collapses into one. Same boundary. Same install path. Same kill switch (close the window). The per-agent sandbox question goes away — the answer is the same for every variant on this list: install nilbox once, then install the agent inside it the way its README says. One sandbox, ten agents.


Three Honest Exceptions

Three places where the "just put it in nilbox" recipe doesn't apply:

Agent Why it's an exception
Moltworker Already runs serverless inside Cloudflare's own sandbox. There's no local install for nilbox to wrap. Isolation is Cloudflare's problem, not yours.
NullClaw on a Raspberry Pi / edge device You explicitly chose bare metal because you have a 1MB RAM budget and a 2ms boot target. Running it inside a desktop VM defeats the entire point of picking NullClaw.
NanoClaw Docker-based by design. Docker doesn't run inside the nilbox VM. With NanoClaw you've already bought into one isolation model (containers) — pick that or pick nilbox + a non-Docker-bound agent, but you can't stack them.

For everything else on this list — every install you'd otherwise drop directly onto your laptop or workstation — nilbox is the layer underneath.


How to Choose in Two Minutes

  • Most features, don't mind the size? OpenClaw.
  • OpenClaw's idea + real container isolation? NanoClaw.
  • Want the agent to learn your habits over time? Hermes Agent.
  • Want to read every line yourself? Nanobot or PicoClaw.
  • One binary that runs from a Pi to a workstation? ZeroClaw, or NullClaw if you really need it tiny.
  • Lying-awake-paranoid about prompt-injection exfil? IronClaw — and even then, run it inside a sandbox.
  • Don't want anything on your machine? Moltworker.

Then, regardless of which: wrap it in a VM and a token boundary. That last step is the same for all ten (with the three exceptions above).


FAQ

Is OpenClaw safe to run directly on my main machine?
Not really. The shared-process, application-level permission model means a misbehaving skill — including one nudged by prompt injection — can reach files and tokens it shouldn't. Run it inside a VM (or nilbox) and you sidestep that entire class of problem.

OpenClaw vs. Hermes Agent — what's the actual difference?
OpenClaw is broader and more reactive: lots of skills, low setup overhead, no native learning system. Hermes is narrower and more cumulative: fewer out-of-the-box integrations, but every successful task becomes a reusable skill, and the agent gets better at your workflows over time.

Can I run NanoClaw without Docker?
Not really. Container isolation is the whole pitch — without it you're running a smaller OpenClaw with no isolation upgrade. On macOS, Apple Container works as a Docker substitute.

Can I stack nilbox on top of NanoClaw's container isolation?
No. NanoClaw is Docker-based and Docker doesn't run inside the nilbox VM. Pick one or the other.

Who's winning on raw popularity right now?
By stars, OpenClaw (345k+). By growth rate, Hermes Agent (110k in 10 weeks). By Reddit consensus on "what should I actually run?", NanoClaw — for the security reasons above.


Try It

  • Install nilbox: docs.nilbox.run
  • Source: github.com/rednakta/nilbox — bridge, proxy, VM image, store manifest, all open source
  • Pick an agent above that fits your taste, drop it into the nilbox store, done

The *Claw ecosystem is the most exciting thing to happen to personal computing in years. A real agent on your hardware, talking to your messaging apps, talking to local models, doing actual work. Pick one whose tradeoffs match your taste. Run it in a sandbox. That's the whole answer.


Further Reading