惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
S
SegmentFault 最新的问题
L
LangChain Blog
Simon Willison's Weblog
Simon Willison's Weblog
N
News and Events Feed by Topic
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
WordPress大学
WordPress大学
M
MIT News - Artificial intelligence
A
About on SuperTechFans
Microsoft Security Blog
Microsoft Security Blog
I
Intezer
Know Your Adversary
Know Your Adversary
H
Heimdal Security Blog
博客园 - 叶小钗
B
Blog RSS Feed
F
Fortinet All Blogs
Hacker News: Ask HN
Hacker News: Ask HN
A
Arctic Wolf
小众软件
小众软件
Help Net Security
Help Net Security
MongoDB | Blog
MongoDB | Blog
aimingoo的专栏
aimingoo的专栏
G
Google Developers Blog
Forbes - Security
Forbes - Security
Latest news
Latest news
AI
AI
I
InfoQ
H
Hackread – Cybersecurity News, Data Breaches, AI and More
C
CXSECURITY Database RSS Feed - CXSecurity.com
W
WeLiveSecurity
C
Cybersecurity and Infrastructure Security Agency CISA
人人都是产品经理
人人都是产品经理
Cyberwarzone
Cyberwarzone
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
J
Java Code Geeks
Engineering at Meta
Engineering at Meta
C
Cyber Attacks, Cyber Crime and Cyber Security
O
OpenAI News
博客园 - 【当耐特】
T
Threat Research - Cisco Blogs
GbyAI
GbyAI
U
Unit 42
D
Darknet – Hacking Tools, Hacker News & Cyber Security
G
GRAHAM CLULEY
Apple Machine Learning Research
Apple Machine Learning Research
宝玉的分享
宝玉的分享
Google DeepMind News
Google DeepMind News
T
Threatpost
T
The Blog of Author Tim Ferriss
罗磊的独立博客

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
OpenClaw - Here's the best setup guide you'll ever need.
Paimon · 2026-04-26 · via DEV Community

This is a submission for the OpenClaw Writing Challenge

before you install anything

straight in - you need three things ready before you even touch a terminal.

  1. AI model API key
    openclaw works with multiple model providers.
    you're not locked to one.
    here's what's available right now:

    1. and my pick - anthropic (claude) - the best overall for agents. opus 4.6 is the smartest model available and what i recommend for setup. sonnet 4.6 is cheaper and handles everyday tasks well. console.anthropic.com
    2. openai (GPT-5.4) - strong alternative. great tool calling, solid all-rounder. a lot of people switched here last week when anthropic cut off subscription access - also where the founder of OpenClaw now works. platform.openai.com
    3. google (gemini 2.5 pro) - good for long context tasks. generous free tier to get started. worth having as a backup or starting point if budget is tight. aistudio.google.com
    4. *ollama *(local models) - run gemma 4 or other open source models directly on your machine. completely free. not frontier quality but handles routine agent tasks without breaking a sweat
    5. *deepseek *- strong reasoning model from china. very competitive pricing. worth looking at if you want a cheaper alternative to opus for complex tasks

my recommendation: start with anthropic (opus 4.6) as your primary. it's the king of models for agent work. load $250 in API credits to get from zero to fully operational without hitting rate limits - new API customers get lower limits by default and putting real money in upfront avoids that bottleneck while you're building. even $50 gets you started if budget is tight.

  1. a groq API key (for voice notes)
    this is separate from your main model. groq powers the voice note transcription through the whisper plugin - it's how your agent understands your voice messages on telegram. you'll use this constantly.
    it's free. sign up at console.groq.com and grab your API key.

  2. a web search API key
    your agent needs to search the internet. here are your options:
    brave search - ~$5/month. reliable, fast, best value for money. my recommendation. brave.com/search/api
    tavily - has a free tier. built specifically for AI agents. tavily.com
    firecrawl - search plus full page scraping in one tool. firecrawl.dev
    SearXNG - completely free. self-hosted. more setup work but zero cost forever
    my recommendation: brave search. it's been the most reliable and the best bang for your buck in my experience. if you want completely free, tavily's free tier works.

installing openclaw

open terminal and run:

  • on windows (powershell): iwr -useb https://openclaw.ai/install.ps1 | iex
  • if you're on a brand new mac mini or mac device, you might need to install homebrew first, using this terminal prompt: /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"

once openclaw is installed, run the setup wizard:
openclaw onboard
this walks you through everything step by step. here's what to pick:
provider: select anthropic and paste your API key.

model: select opus 4.6. or whichever model you're choosing - but opus is what i recommend for the setup phase. you want the smartest brain available while you're building the foundations.


communications: you'll be asked to set up a messaging platform. for this guide we're going with telegram - it's honestly the easiest. but you can skip this step if you want. i actually find it easier to do the telegram part manually in its own step later since you need to pair it anyway.
skills to preload: this is where most guides just say "install clawhub" and move on. don't do that. install these:

  • clawhub - the skill marketplace
  • mcporter - MCP tool routing
  • openai-whisper - voice transcription (essential for voice notes)
  • model-usage - track what your agent is spending
  • github - if you use git at all, get this in now
  • nano-pdf - PDF reading and processing additional APIs (notion, elevenlabs, etc): skip all of these. you don't need them yet. hooks: enable all four:

  • boot-md - loads your config files on startup
  • bootstrap extra files - sets up your workspace structure
  • command-logger - tracks what your agent runs
  • session-memory - remembers context across sessions once you continue through these steps, you should see the option to hatch in TUI. this is the moment your agent comes to life in the terminal chat window. do it.

say hello. give it a name. watch it respond.
that first reply is a proper magic moment. enjoy it.

connecting telegram

now you've got a living agent in your terminal. but you don't want to live in the terminal. you want it on your phone.
here's the move. tell your agent exactly this:
"okay [agent name], we're going to use telegram to finish setting up and onboarding. next i will send you the API key for my telegram bot and you can install the telegram communication skill for me using it."
now go set up the bot:

  1. open telegram and message @botfather
  2. send /newbot
  3. pick a name and username for your bot
  4. BotFather gives you an API key - copy it go back to your agent in the TUI and paste the API key in with the message above (or right after it). your agent will install the telegram plugin for you. once it's done, head to telegram and open your new bot. click start - you'll see a PAIR code. copy that pair code and paste it back to your agent in the TUI. it handles the rest - pairing, syncing, connecting everything. now go back to telegram and send "hi." watch your agent reply. welcome to a much better and cleaner way to communicate with your agent from anywhere and everywhere. this is how i run everything now.

the best and most practical way to set up your agent from birth

now you have telegram connected, we're going to run through the setup that actually matters. in this order:

  1. install kickstart i built a skill called kickstart that saves you the first 4 hours of pain in openclaw. it's free on clawhub. tell your agent: install the kickstart skill by jordymaui from clawhub here's what it gives you:
  • SOUL.md - your agent's personality file. who it is, how it talks, what it cares about. without this your agent sounds like every other generic chatbot
  • USER.md - information about you. your name, timezone, preferences, what platforms you use. your agent reads this so it knows who it's helping
  • AGENTS.md - the operating manual. rules for how your agent behaves, when to speak, when to stay quiet, how to handle memory
  • TOOLS.md - local notes about your specific setup. camera names, API details, device info - anything unique to your environment
  • HEARTBEAT.md - a checklist your agent reviews periodically to stay proactive instead of just waiting for you to ask things
  • kickstart doesn't just create these files - it guides your agent through filling them out properly. go ahead, install it and move to the next step.
  1. install QMD
    next up - making sure you have QMD installed.
    install the QMD skill from clawhub
    QMD upgrades your agent's memory system with semantic search. instead of your agent scanning through flat text files trying to find what you said three weeks ago, it can actually search by meaning. "what did i say about the budget?" just works. without QMD, your agent's memory is a filing cabinet with no labels. with it, everything is indexed and searchable.

  2. your onboarding session
    this is the most exciting part and honestly the step that makes the biggest difference.
    here's what i always recommend - from brand new beginners to the companies i've consulted for building openclaw systems. send your agent this:
    before we do anything else, i need you to understand who i am and what we're building together. create a questionnaire - no more than 20 direct questions - covering who i am, what i do, how i work, what i need from you, and what your role is going to be. keep the questions short and clear. i'm going to answer all of them in one voice note so make sure they flow naturally as a conversation. after i reply, write everything you learn into your memory files so you never have to ask again.
    your agent will come back with a list of questions. now here's the important bit:
    reply with a voice note. not text. voice.
    talk off the cuff. be casual. pause when you need to think. your agent picks up on how you communicate, what you care about, and what's actually on your mind.
    if you're not sure what the agent's use case is yet - just say that. talk to it like it's a mate and you're thinking through potential ideas together. there is genuinely no wrong answer here as long as you're open, honest, and giving it real context about your life.
    this one voice note will give your agent more useful information than weeks of typed messages. i learned that the hard way.

best practices from 500+ hours of daily use

model routing

don't run everything on opus. it's the best model but you don't need the best for every task.
set up your config so opus handles the complex stuff - reasoning, multi-step tasks, creative work. sonnet or groq handles the routine stuff - calendar checks, simple lookups, monitoring, notifications.
this alone cut my monthly cost in half. your agent routes automatically once it's configured.

keep CLAUDE.md short

this file gets re-injected every single message your agent processes. the leaked claude code source confirmed it. if yours is 2000 words of life story, you're burning tokens and confusing your agent on repeat.
mine is 6 lines. name, role, communication style, three rules. everything else lives in skills and memory files where the agent pulls it when it needs it.

split agents by job

if you're doing more than 3-4 different things, use separate agents. one agent scanning twitter, managing data, writing content, handling emails, and running cron jobs - it works for about two weeks before context starts bleeding between tasks and everything slows down.
dedicated agents for dedicated jobs. cleaner context, faster responses, fewer mistakes.

read your memory files

your agent writes notes about you after every conversation. check them weekly. you'll catch when it has the wrong idea about something before it acts on it. it's like reading your assistant's diary - sometimes spot on, sometimes hilariously wrong.

update regularly

nine CVEs dropped for openclaw in one week last month. one scored 9.9 out of 10. run openclaw update weekly. not optional.