What ZeroClaw is
ZeroClaw is an open-source personal agent runtime distributed as a single native binary. Its argument is that most assistants are seats rented on somebody else's machine, while this one is a file you run yourself. It is the most engineering-forward entry in this batch.
What it does
One binary with no language runtime dependency pairs with dozens of model providers, both local and hosted, and dozens of messaging channels. The loop is install, configure, run.
It advertises near-instant cold start, memory use below what a browser tab consumes, operation on very low-power hardware down to single-board computers, and control of hardware pins and microcontrollers, with a kernel where providers, channels, tools, memory and tunnels are configurable.
The governance design is the notable part. Autonomy is supervised by default, so medium-risk actions need approval and high-risk ones are blocked. There is operating-system sandboxing, explicit command whitelists scoped to a workspace, and optional signed receipts for successful tool calls, where the agent cannot see the signing key so fabricated execution leaves a missing or invalid receipt. An unrestricted mode exists and is explicitly not the default.
Who it is for
It is aimed at developers, privacy-focused individuals and hardware tinkerers who want a portable agent runtime, and at anyone who would rather read the policy file than trust a vendor's summary of it.
What to keep in mind
The software is free under a permissive dual licence with no subscription and no vendor cloud in the middle, so with local models it can cost nothing and data need not leave the device. That is a strong position and it also means nobody else is maintaining your deployment.
The page lists no compliance certification and its performance figures are self-reported, so benchmark them yourself rather than planning around vendor numbers.
Two practical cautions. The documented install path pipes a remote script into a shell and then starts a long-running gateway and daemon that open webhooks and messaging connections, which enlarges the attack surface, so read the script, pin the version and limit exposed ports. And the optional unrestricted mode lets the agent execute medium-risk operations, including shell tools, without approval, so enabling it is a deliberate risk decision rather than a convenience setting.
Signed receipts are a genuinely useful idea, and they detect fabrication rather than proving safety, so keep the other controls in place. Governance in a self-hosted runtime is only as good as the configuration you actually run: supervised autonomy by default is a sensible starting point, and the approval thresholds are values you can change, so treat the defaults as a beginning rather than an assurance. Confirm the licence and the exposure too, since a dual licence may carry different terms for commercial use.
Pros & cons
✓ What we like
- Single binary, dual-licensed and free, with no vendor cloud in the middle
- Supports dozens of providers and messaging channels, including local models
- Approval-gated autonomy, sandboxing and command whitelists by default
- Optional signed receipts to detect fabricated tool execution
! What to watch out for
- No compliance certification, and performance figures are self-reported
- Install path pipes a remote script into a shell and starts an exposed daemon
- Unrestricted mode removes approval for medium-risk operations
FAQ
What does supervised autonomy mean?
Medium-risk actions require approval and high-risk ones are blocked by default. An unrestricted mode exists and is explicitly not the default.
What do the signed receipts prove?
That a tool call actually executed, since the agent cannot see the signing key. They detect fabrication, not unsafe behaviour.
Is the install safe?
The documented path pipes a remote script into a shell and starts a daemon with webhooks. Read the script, pin the version and limit ports.
Last reviewed: 2026-09-19
More OpenClaw & desktop agents tools
View all →-
360安全龙虾(Security Claw) Agent security sandbox that isolates OpenClaw-style agents from the host system Free tools Agent Developer tools Openclaw skills Security -
360龙虾卫士 Runtime guard that monitors AI agent file, process, network and screen activity Free tools Agent Workflow automation Openclaw skills Security -
ArkClaw Volcano Engine Doubao models Free tools Workflow automation API integration Multi model platform Openclaw skills -
AstronClaw iFLYTEK AI office assistant Open source tools Agent Workflow automation Developer tools Openclaw skills -
AutoClaw A general agent that researches, writes and executes tasks Free tools Agent Personal assistant Workflow automation Openclaw skills -
BoClaw Enterprise AI office platform Agent Workflow automation Developer tools Office productivity Openclaw skills