security
Apr 24, 2026
By Teun
OpenClaw Surges on GitHub as Self-Hosted AI Agent Gateway
OpenClaw, a self-hosted AI agent gateway written in TypeScript, has become GitHub’s most-starred non-aggregator software project after reaching 355,000 stars in about five months. According to the source article, the project runs on developer-owned hardware, connects to more than 50 messaging platforms, and can execute shell commands, file operations, and API calls.
OpenClaw has become one of the most closely watched open-source AI projects of 2026. According to the source article, the TypeScript-based, self-hosted agent gateway passed React on March 3, 2026, to become GitHub’s most-starred non-aggregator software repository, reaching 355,000 stars in under five months.
The project is designed to connect large language models to messaging platforms such as WhatsApp, Telegram, Slack, iMessage, Signal, and Discord, while also letting the agent carry out real tasks on hardware the user controls. That includes shell commands, file operations, browser actions, and API calls.
OpenClaw was created by Austrian developer Peter Steinberger, founder of PSPDFKit. The source article says it began as a weekend experiment called Clawdbot in November 2025, then was renamed and released under an MIT license after a trademark dispute in late January 2026.
The appeal, according to the article, is ownership and persistence. OpenClaw is built for a personal assistant that can run 24/7 on a device such as a Mac Mini, keep session memory across channels, and handle background tasks without sending data through a third-party cloud service.
Technically, OpenClaw uses a single TypeScript process called the Gateway. It opens a WebSocket server on port 18789, receives messages from connected channels, matches them to a session context, forwards them to a chosen model, executes any tool calls the model requests, stores relevant memory in local markdown files, and sends the response back to the original channel.
The source article contrasts that model with LangGraph, which supports more advanced multi-agent orchestration. OpenClaw trades that complexity for simpler setup and a lower barrier to entry, especially for solo developers who want one runtime they can inspect and run themselves.
OpenClaw also supports 25-plus model providers, including GPT-4o, Claude 3.5 Sonnet, Gemini 1.5, DeepSeek V3, and local models through Ollama. Skills are defined in markdown files, while plugins are distributed as npm packages. That means non-TypeScript users can extend behavior without writing much code.
Adoption has accelerated quickly. The article says OpenClaw has 3.2 million reported active users and more than 500,000 running instances as of April 2026. It also cites community attention on Hacker News, Reddit, and GitHub Discussions, plus more than 15 arXiv papers in the first three months of visibility.
Setup is described as relatively fast. The source article says developers need Node.js 22.16 or later, then can install the CLI with npm or pnpm and run an onboarding wizard that configures the gateway, workspace, channel pairing, and first skill. Telegram can be paired with a bot token, while WhatsApp uses a QR code flow.
The project’s security posture is the main caution. According to a February 2026 arXiv preprint cited in the article, OpenClaw defended against 17% of adversarial prompt injection scenarios in testing. The project documentation also states that there is no “perfectly secure” setup.
The article says the biggest risk is prompt injection through untrusted channel content, since malicious messages can influence an agent that is allowed to run commands. It also warns about supply-chain risk from community skills and npm plugins, and says production-critical deployments should be version-pinned and tested in isolation before upgrades.
The source article frames OpenClaw as a strong fit for developers and ML engineers who want a personal AI agent on hardware they control. For enterprise teams handling sensitive data or regulated workflows, it says the project is not ready for unrestricted production use.