mrkeyoor.com_
Thu 01 Oct 10:58 UTC
LLM Toolsevaluationupdated 26 Aug 2026

zeroclaw review

ZeroClaw is a self-hosted personal assistant that connects language models to chat channels, local tools, browser tasks, memory, and scheduled procedures. One Rust program can answer through services such as Telegram or Matrix, use hosted or local models, and ask for approval before riskier actions.

+36stars / 7d
Verdict

Our ZeroClaw build took 431 seconds and 407 of 408 tests passed; the lone failure came from a release script calling an absent jq, so serious self-hosters have a promising build with one concrete packaging prerequisite to fix. Choose it when channel reach, provider choice, and approval-gated procedures justify owning a 912,596-line agent runtime. Wait if you need a small attack surface or a project with years of operational history.

We ran it

Lab card: what happened when we ran zeroclawScreenshot of zeroclaw (www.zeroclawlabs.ai)
Install✓ · 59s469 packages
Build✓ · 431s
Tests✗ · 625s407 passed · 1 failed of 408 (cargo test)
Repo1855 files~912,596 lines of source · 74.3 MB · 27 CI workflows · Dockerfile · tests dir

Answers from our run

Does zeroclaw build from source?

Dependencies installed in 59 seconds (469 packages), and the build succeeded in 431 seconds. We cloned commit 3d7a3b1 into a clean Debian container with 3 CPUs and no project-specific setup.

Do zeroclaw's tests pass?

Not all of them: 407 of 408 passed and 1 failed when we ran the project's own test command (cargo test). Some failures need services or credentials a bare container does not have.

Who should not use zeroclaw?

People seeking a simple chat application: the minimum V3 configuration still needs provider, agent, and risk-profile sections, while useful deployments add channel credentials and service management.

What are the alternatives to zeroclaw?

OpenClaw, nanobot, Khoj. Our ZeroClaw build took 431 seconds and 407 of 408 tests passed; the lone failure came from a release script calling an absent jq, so serious self-hosters have a promising build with one concrete packaging prerequisite to fix.

Setup3/5Quickstart helps, but channels, policies, and services add work
Docs4/5Detailed setup, config, architecture, security, and channel guides
Community5/5Current commits and rapid issue and pull-request activity
Maturity3/5Broad capability in a repository created only in February 2026

Discussed on

  1. hnZeroClaw - Zero overhead. Zero compromise. 100% Rust.6 points

Who it’s for

Experienced self-hosters who want one personal agent across chat, terminal, web, and editor surfaces.
Rust-friendly operators who need provider choice, local data control, and explicit approval policies.
Automation teams that can use event-driven procedures with checkpoints for cron, webhooks, MQTT, or hardware.
Developers connecting custom Model Context Protocol servers or physical devices to an agent runtime.

Who it’s NOT for

People seeking a simple chat application: the minimum V3 configuration still needs provider, agent, and risk-profile sections, while useful deployments add channel credentials and service management.
Operators unwilling to audit a fast-changing security boundary: issue 10320 says two configuration write paths can persist values without validation.
Teams that cannot test cancellation and recovery behavior: issue 10316 says an exhausted step budget can overwrite an accepted SOP cancellation as failed.
Anyone who plans to enable YOLO mode on a machine holding valuable data: the README says that mode skips the normal safety gates and limits it to trusted development boxes.
Buyers who need years of stable release history: the repository was created in February 2026 and already has hundreds of open issues and pull requests.

Setup reality

Our Rust sandbox installed 469 packages in 59 seconds and built ZeroClaw in 431 seconds. Tests ran for 625 seconds: 407 of 408 passed. The sole failure said jq was missing when a Scoop metadata script tried to validate its autoupdate URL.

A useful installation also needs a model provider or local model, credentials for each channel, a TOML configuration, and a risk profile. Always-on use adds a system service, secret rotation, backups, and monitoring.

Commit 3d7a3b1 occupied 74.3 MB but contained about 912,596 source lines across 1,855 files. Docker and Compose files exist, yet hardware, browser, messaging, and OS sandbox features still need platform-specific checks.

What happened when we ran it

In our unprivileged Debian sandbox with no secrets, we installed 469 Rust packages in 59 seconds, then built commit 3d7a3b1 successfully in 431 seconds. The checkout was 74.3 MB, but its 1,855 files contained about 912,596 source lines. That is a large ownership commitment for software presented as one deployable binary.

Tests ran for 625 seconds. Cargo reported 407 passed and 1 failed out of 408. The failure was specific: release_workflow::scoop_publisher_metadata_follows_canonical_url_template called scripts/release/scoop_metadata.sh, which stopped because jq was not installed. The test then could not confirm a non-empty, single-line Scoop autoupdate URL. Our clean Debian container exposed a missing system-tool assumption in the release path; it did not show a failure in the agent loop.

One binary connects more than 20 model providers and 30 channels

ZeroClaw runs an agent loop around Anthropic, OpenAI, Ollama, and roughly 20 other provider options. More than 30 channel adapters cover chat services, email, voice, webhooks, CLI access, and Agent Client Protocol links to editors. Tools include shell, browser, HTTP, hardware, and custom MCP servers. A gateway and dashboard add chat, memory browsing, configuration, cron management, and tool inspection.

This breadth is the reason to consider it. A single assistant can keep its memory and policies while the user moves between Telegram, a terminal, and an editor. Provider fallback chains can also reduce dependence on one model service. Each adapter brings credentials, rate limits, formatting differences, and another failure mode, so using 30 channels should never be the goal. Configure only the routes you can monitor.

Supervised mode blocks high-risk actions by default

The default autonomy level is supervised. Medium-risk operations require approval and high-risk ones are blocked. Workspace boundaries, command policy, operating-system sandboxes, and cryptographic tool receipts give operators several places to constrain actions and reconstruct what happened. Linux can use Landlock or Bubblewrap, macOS can use Seatbelt, and Docker is another boundary.

The README also documents YOLO mode, which skips normal gates for trusted development machines. That escape hatch is useful for disposable workspaces and dangerous on a personal server with messages, API keys, browser sessions, and shell access. A good deployment starts with one agent, one provider, one channel, and the smallest tool policy that completes the task. Add permissions after reviewing receipts, not before.

SOP approvals make automation useful and expensive to operate

Standard Operating Procedures can start from cron, webhooks, MQTT, or peripheral events. They support approval gates and resumable runs, which gives deterministic work a clearer shape than asking an open-ended agent to remember every step. Release 0.8.4 added admission policies, quorum approval brokering, checkpoint editing, and further memory controls.

The issue queue shows why those controls need testing. Issue 10316 says step-budget exhaustion can replace an accepted cancellation with a failed state. Issue 10320 says config set and an RPC configuration path can persist values without running validation. Neither report proves a general reliability problem. Both touch operator trust, so cancellation, configuration rollback, and approval handling belong in acceptance tests before an SOP reaches production.

February 2026 origins make the pace impressive and risky

The repository was created on February 13, 2026, pushed on August 26, and released version 0.8.4 on August 2. GitHub listed 802 open issues and pull requests, with fixes and bug reports changing by the minute on August 26. More than 32,000 stars show attention, while the dated push and issue activity show that maintenance is current. Six months of history cannot establish long-term stability.

Documentation is unusually deep for that age. The README links setup guides for major platforms, a generated configuration reference, provider and channel guides, security policy, architecture, and an RFC process. The minimum V3 setup still needs a provider alias, an agent that references it, and a risk profile. Quickstart writes the first configuration, but operators must understand it before granting tools access to a real machine.

Credential paths also differ by provider. The README documents importing an existing OpenAI Codex auth profile, using a Claude setup token in the Anthropic slot, and supplying an API key only when an OpenAI entry deliberately targets a custom compatible endpoint. That separation reduces accidental misconfiguration, but it gives backups and incident response more than one secret location to cover. Run zeroclaw auth status and test provider fallback before installing the always-on service.

ZeroClaw is worth a controlled trial for an experienced self-hoster who wants one assistant across channels and accepts the work of policy design. The 407 passing tests and explicit sandbox model are encouraging. The 912,596-line codebase, young history, and current configuration and SOP reports argue for a narrow rollout with pinned releases, backed-up configuration, and rehearsed recovery.

Alternatives

ProjectWhat it isPick it when
OpenClaw gh↗A self-hosted personal assistant centered on a gateway, messaging channels, tools, and device companions.pick this instead when its established gateway ecosystem and device integrations fit your channels better.
nanobot gh↗A smaller personal AI assistant built for readable code and lightweight deployment.pick this instead when a compact codebase matters more than ZeroClaw's SOP, hardware, and policy surface.
KhojA self-hostable assistant focused on personal knowledge, search, agents, and chat access.pick this instead when searching personal documents is the main job and fewer action channels are acceptable.

What people are saying

  1. [velocity-scout] zeroclaw-labs/zeroclaw

Sources

  1. ZeroClaw repository and README
  2. ZeroClaw v0.8.4 release
  3. Configuration writes bypass validation report
  4. SOP cancellation state report
  5. ZeroClaw security documentation

More llm tools reviews

claude-style-patch · agent-toolkit-for-aws · agent-memory · codex-astra-luna-orchestrator · okf-agent-memory · mlc-llm · the whole board →