What is OpenClaw? Skills, ClawHub and staying safe

By Tried AI Tools · Published · Updated

Short answer

As of October 2026, OpenClaw is a free, MIT-licensed AI agent that runs on your own computer and takes orders through chat apps like WhatsApp, Telegram, Slack and Discord. Version 2026.9.7 ships with 49 built-in skills, and thousands more sit on the ClawHub registry. The software costs nothing, but you pay for the AI model you plug in, and third-party skills should be treated as untrusted code.

Based on the official documentation as of October 2026, this guide explains what OpenClaw is and what its add-ons are called. It also covers what it costs and how to use it without getting burned. For a full list of built-in and notable community skills, each with a one-line summary, see the OpenClaw skills directory.

What OpenClaw is

OpenClaw is free, open-source software that turns an AI model into a personal assistant that acts for you. It runs on your own computer or server. You talk to it through chat apps you already use, and it can handle email, calendars, files, web browsing and terminal commands. It is not an AI model itself.

Beyond chat, the docs list scheduled jobs (cron, hooks and webhooks), built-in memory, several agents with separate workspaces, and a web Control UI for chat and settings.

The official site calls it "The AI that really does things." It lists WhatsApp, Telegram, Discord, Slack, iMessage and Signal, and the channels docs list more than 30 chat apps in all. The code is on GitHub under the MIT license.

A short history

Peter Steinberger first published the project on November 24, 2025, as Warelay, according to Wikipedia. It became Clawdbot on January 2, 2026, then Moltbot on January 27 after trademark complaints from Anthropic. The OpenClaw name followed days later; the official launch post is dated January 29, 2026.

Steinberger joined OpenAI in February 2026. Sam Altman said OpenClaw would "live in a foundation as an open source project that OpenAI will continue to support". The OpenClaw Foundation officially launched as a US 501(c)(3) nonprofit on July 8, 2026, with Dave Morin as chair.

The project moves fast. OpenClaw 2.0 (version 2026.8.1) shipped on August 30, 2026. The latest release, 2026.9.7, was published on npm on September 30, 2026. It added Sign in with ChatGPT (Beta) and a plugin for OpenAI's Agents API.

The parts, in plain words

OpenClaw has a handful of moving parts. The Gateway is the engine on your machine. Channels are the chat apps it talks through. Skills teach it how to do specific jobs. Plugins add deeper features in code. ClawHub is the public store where people share skills and plugins.

Term What it means
Gateway The background service that runs your agent, keeps sessions and connects to chat apps. It uses port 18789 by default.
Channel A chat app OpenClaw talks through, such as Telegram, WhatsApp or Slack.
Node A paired companion device, such as the macOS menu bar app or an iOS or Android phone, that lets the agent use its camera, screen and notifications. Nodes do not run the Gateway themselves.
Skill A folder with a SKILL.md file: plain-text instructions, plus optional scripts, that teach the agent a task.
Bundled skills The 49 skills that ship inside the openclaw 2026.9.7 package, such as github, weather and summarize.
Plugin A code package that adds model providers, chat channels, memory or tools.
ClawHub The official public registry at clawhub.ai for skills and plugins.
Custodian A configured admin agent with extra operational skills only it can use, such as setting up channels and model providers or diagnosing the Gateway.

How skills work

A skill is a short instruction file that tells the agent how and when to use a tool. The skills docs say skills load from your workspace, your personal folder, managed installs and the bundled set. If two skills share a name, the higher-priority location wins.

Most bundled skills wrap a command-line tool. They only switch on when that tool is installed.

What ClawHub is

ClawHub is "the public registry for OpenClaw skills and plugins." Anyone with a GitHub account "old enough to pass the upload gate" can publish. Each listing shows versions, downloads and security scan summaries. Official company publishers include NVIDIA, Amazon Web Services, Hugging Face, Shopify and Expedia Group, per ClawHub's official publishers page.

How to install it and what plan you need

You need no plan or account with OpenClaw. You need a Mac, Linux or Windows machine, and an AI model to connect. The one-line installer sets up Node for you and starts a setup wizard. Then you pick a model and a chat app.

The install docs give these commands. Prefer an app? The same page also offers a macOS .dmg and a Windows Hub companion app, and you can pair iOS and Android phones as nodes.

  1. On macOS, Linux or WSL2, run curl -fsSL https://openclaw.ai/install.sh | bash.
  2. On Windows PowerShell, run iwr -useb https://openclaw.ai/install.ps1 | iex.
  3. If you manage Node yourself (24.16+ or 26.1+, Node 26 recommended), run npm install -g openclaw@latest --allow-scripts=openclaw, then openclaw onboard --install-daemon.
  4. During onboarding, connect a model: an API key from Anthropic, OpenAI, Google or another provider, or a local model.
  5. Telegram and WebChat are built in. For others, install a plugin, for example openclaw plugins install @openclaw/discord.

To add a skill from ClawHub, run openclaw skills install @owner/<slug>. Check it first with openclaw skills verify @owner/<slug>. Update everything with openclaw skills update --all.

What it costs

OpenClaw itself is free. The homepage says "No subscription. No hosted tier." Your real costs are the AI model, any paid services your skills call, and hosting if you rent a server. A fully local setup can cost nothing beyond your own hardware and electricity.

Cost item What to expect
OpenClaw software Free, MIT licensed
AI model Pay-as-you-go to your provider, or free with a local model
Claude Since April 4, 2026, Anthropic says subscription limits do not cover third-party harnesses like OpenClaw; an API key (pay-as-you-go) is the standard route
ChatGPT Sign in with ChatGPT is in beta as of 2026.9.7
Meta Muse Spark Via the @openclaw/meta-provider plugin, billed by Meta
Skills that call paid APIs For example ElevenLabs voices or Google Places, billed by those companies
Hosting Only if you run it on a rented server

To compare model prices, see AI chatbot prices compared. To weigh a local setup, see local AI vs subscription cost and run your first local LLM on a Mac with Ollama.

Who it is for

OpenClaw suits people who are comfortable with a terminal and want an assistant they control. It fits tinkerers, developers and small teams who trust each other. It is a poor fit if you want something that just works out of the box, or if you cannot spare time to secure it.

The security docs describe "one trust boundary per gateway": one person, or a team whose members trust each other. Larger companies can pilot OpenClaw Enterprise, a free, open-source platform announced September 29, 2026. It is pre-1.0 and not a paid edition; the homepage says there is no paid version.

How to stay safe

OpenClaw can read your email, run commands and touch your files. That power is the risk. Third-party skills have shipped real malware, and thousands of Gateways were left open to the internet in early 2026. Use bundled skills where you can, check every add-on, and keep the Gateway private.

What happened:

What changed: ClawHub now scans every skill with VirusTotal and rescans active skills daily. Its ClawScan pipeline combines static analysis, VirusTotal and NVIDIA SkillSpector, and rates each skill Clean, Suspicious or Malicious. An NVIDIA Skill Card shows who published it, what it can do and what the scan found. Signed-in users can report skills, and moderators can hide content and ban abusive accounts, per the ClawHub docs. A Trail of Bits audit found 0 critical and 2 high-severity issues, all fixed in 2026.8.1 and 2026.7.33 LTS (long-term support).

Practical steps:

  1. Read a skill's SKILL.md before you enable it. The docs say: "Treat third-party skills as untrusted code." Never run a command a skill suggests unless you understand it.
  2. Check the ClawHub page's scan results and publisher, and install with the full @owner/slug name to avoid look-alikes.
  3. Remember that scans are not a guarantee. The VirusTotal partnership post warns that a skill using plain-language malicious instructions "won't trigger a virus signature."
  4. Keep the Gateway on its default loopback setting with auth on. For remote access, the network docs recommend Tailscale Serve. Never expose it unauthenticated on 0.0.0.0.
  5. Turn on sandboxing, which is off by default, so the agent's commands run in an isolated backend instead of directly on your computer. The sandboxing docs list Docker, Podman, SSH and OpenShell backends, among others.
  6. Run openclaw security audit after setup and after any change. Add --deep for live checks or --fix to apply safe fixes (CLI docs). Keep OpenClaw updated.
  7. Give the agent the least access it needs. A separate account or machine is safer than your main email and wallets.

Limits to know

OpenClaw is powerful but rough around the edges. Setup takes real effort, security is your job, and every skill adds to prompt costs. Emails and web pages the agent reads can contain hidden instructions, a risk called prompt injection. Some governments and employers restrict it.

In March 2026, Chinese authorities restricted state-run enterprises, government agencies and banks from running OpenClaw on office computers, Wikipedia reports. The project ships updates very often, so commands and defaults can change between releases.

Related guides

These guides cover the other big agent and chatbot ecosystems, plus local AI options for running models on your own hardware. Start with the comparison if you are still choosing a tool. Use the OpenClaw skills directory when you are ready to add skills, since it gives a one-line summary of each.

Sources

Frequently asked questions

Is OpenClaw free?

Yes. The software is free and MIT licensed, and the official site says there is no subscription and no hosted tier. You pay your AI model provider per use, plus any paid APIs your skills call and any server you rent. Local models through tools like Ollama cost nothing beyond your hardware.

Is OpenClaw the same as Clawdbot or Moltbot?

Yes. It is the same project under a new name. Wikipedia says it was first released in November 2025 as Warelay and became Clawdbot in January 2026. It was renamed Moltbot on January 27, 2026 after trademark complaints from Anthropic, and became OpenClaw in late January 2026.

Can I use my Claude subscription with OpenClaw?

Mostly no. Since April 4, 2026, Anthropic says Claude subscription limits no longer cover third-party harnesses like OpenClaw, and that usage is billed pay-as-you-go instead. The simplest route is an Anthropic API key, which OpenClaw's docs say uses separate pay-as-you-go billing. OpenClaw also has a Claude CLI option that runs through an installed Claude Code login; check Anthropic's current terms before relying on it.

Are ClawHub skills safe?

Not automatically. In early 2026 researchers found hundreds of malicious skills on ClawHub. Every skill is now scanned, but the official docs still say to treat third-party skills as untrusted code and read them before enabling.

Does OpenClaw work with Meta's Muse Spark models?

Yes. The official @openclaw/meta-provider plugin adds Meta's Muse Spark models, with meta/muse-spark-1.3 as the default. You need a Meta API key, and usage is billed by Meta.