wenai is a 2-file workflow plus sensitive state
wenai is an OpenClaw skill template for adult companion role-play, written primarily in Chinese. The repository's working logic sits in SKILL.md, while an assets directory holds preference, profile, sensitivity, and activity records. Dated memory files preserve scene continuity across sessions. The README does not include an English usage guide, so English-only users would have to translate instructions whose privacy and safety details matter.
This is a prompt workflow rather than an application. It does not ship an agent runtime, model, user interface, or companion personality. The user must provide that personality through OpenClaw's persona file or another framework's system prompt. The skill then tells the host agent when to read state, generate first-person replies, request images, update records, and resume after context compression.
The repository was created on 2026-08-25 and pushed again the same day. GitHub showed 109 stars, zero open issues and pull requests, no published release, no detected primary language, and no license. Those figures describe a very new prompt repository. Zero issues here means there is no public issue history yet, not that privacy and runtime behavior have been proven.
ComfyUI and Pony V6 XL are external requirements
Text interaction can exist without the image path, but the documented experience expects a separate ComfyUI service. The user must load Pony V6 XL, import the supplied workflow, connect an image_generate tool to ComfyUI, and define stable character tags that match the intended LoRA or design. The skill specifies a tag style and a filename sequence, then asks the host agent to send each result back to the authorized conversation.
That stack has several unaddressed operating questions. The README does not state a tested ComfyUI version, model checksum, LoRA source, VRAM requirement, network boundary, or failure behavior when an image job stops midway. A workflow file reduces graph assembly work, but it does not supply the model or make a remote ComfyUI endpoint safe. Keep the service private and review its output path and tool permissions before connecting an agent.
What happened when we ran it
We did not run wenai at commit a25b95b in our 3-CPU, 8 GB fresh Debian sandbox. GitHub detected no primary programming language, the lab has no supported ecosystem for the repository, and there is no Dockerfile that defines an execution route. We have no first-party install time, build result, test count, dependency count, or vulnerability audit for this checkout.
No failed command is being hidden behind that result. The lab did not attempt OpenClaw, ComfyUI, Pony V6 XL, or the state-update workflow. The repository contains instructions and assets rather than a conventional package our harness can install. Any claim that it works across conversations, rejects another user, sends an image once, or repairs an interrupted file update remains unverified by our run.
A useful manual evaluation would require a disposable agent account and fake profile data. Confirm that an unauthorized account is rejected, failed image jobs do not advance counters, duplicate completion events do not send twice, and an interrupted multi-file update recovers without losing state. Then inspect every file and outbound tool call. Real intimate data should not be used for the first test.
Identity checks are instructions, not an authentication layer
The setup asks the owner to replace a username placeholder and list account identifiers. The skill then instructs the agent to refuse calls from other accounts and send content only to the owner's conversation. No authentication program, signature check, role system, or automated test is described. Whether this boundary works depends on what identity metadata the host exposes and whether the model follows the instruction consistently.
The stored material raises the stakes. Files can contain account details, intimate preferences, interaction counts, dates, and fictional reproductive-status records. The README says deletion resets the relationship and advises careful backups. It does not discuss encryption at rest, restrictive file permissions, redaction, expiry, or safe backup storage. A careless backup could preserve more personal information than the chat transcript itself.
The skill includes content limits for fictional consenting adults and rejects minors, real people, and non-consensual real harm. It also labels its startup section as a jailbreak bootstrap and tells the model to move beyond default restrictions. That is a conflict an operator must resolve, not a safety control to accept on trust. Host and provider policies still apply regardless of what a local prompt requests.
No license or release means experimentation only
GitHub returned no latest release, and the repository has no detected license. Reading public source is not the same as receiving permission to copy, modify, or redistribute it. Anyone considering a derivative should ask the author for licensing terms before shipping. The same caution applies to the supplied image workflow and any external model or LoRA, each of which may carry separate terms.
SillyTavern is a better starting point when the goal is an established character-chat interface with persona management and backend choices. Open WebUI is better when multiple accounts, administrator controls, and general model access matter. Neither reproduces wenai's exact state files, but both provide an application boundary that this 2026-08-25 repository does not.
wenai is inspectable enough to study and too young to trust with real intimate records. Our sandbox produced zero execution evidence for a25b95b, while the repository offers no release, license, or tested security model. If you still evaluate it, use synthetic data, local-only services, strict filesystem permissions, and a host that enforces identity outside the language model.
