Sources#
- Andrej Karpathy: From Vibe Coding to Agentic Engineering
- DHH: Future of Programming, AI, Agentic Engineering, Vibe Coding & Linux | Lex Fridman Podcast #501
- Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems
- The New Physics of Business — Garry Tan, Y Combinator
- Thread by @AndrewYNg
Summary#
Open-source personal AI agent and harness created by Peter Steinberger (openclaw.ai) — the project through which he became "OpenClaw's creator" in Andrew Ng's telling of how loop engineering went viral. It runs as a persistent personal agent (Lenny's Newsletter covers it as "the most powerful personal AI tool since ChatGPT"), typically backed by Claude models, with a community skills ecosystem (ClawHub, 500+ skills in practitioner discourse). This page exists because OpenClaw kept accruing load-bearing mentions across the wiki's sources without a home.
Roles it plays across the wiki#
- The canonical agent-native install. Karpathy's go-to example of Software 3.0 / Agent-Native Infrastructure: installing OpenClaw is not a shell script but "a copy-paste of a bunch of text that you're supposed to give to your agent," which inspects the environment and debugs in the loop — the unit of distribution for agent-native software is a prompt/skill, not an executable.
- An institution-scale harness. Per Garry Tan (July 2026), Y Combinator runs internally on OpenClaw plus a company brain; non-engineering staff build skill files on it; his tool ranking: "OpenClaw is the Ferrari… Codex is a really good Honda." His GBrain "works with any harness, but it loves" OpenClaw.
- Evidence for character as product. When Anthropic constrained third-party API access in 2026, capped OpenClaw users expressed loss about Claude's personality specifically — a data point on Claude Character as Product.
- An agent-society precursor. Noam Brown names "Moltbook and OpenClaw" (the project's earlier Moltbot-era social experiment and the agent itself) as overhyped-but-genuine early signs of large-scale agent coordination (Multi-Agent Collective Intelligence).
- A real deployment target for security research. The aiAuthZ gateway validated its deny-path against a live OpenClaw runtime over MCP; a dedicated security analysis ("Don't let the claw grip your hand," arXiv 2603.10387) and an RL-training variant (OpenClaw-RL) exist in the literature (AgentOpt cites both and patches it like any httpx-based framework).
- The reference harness for agent-network security research. Papadopoulos et al. (Anthropic Fellows / EPFL, arXiv 2608.10218,
empirical) build their 'virus chain' — the study's model of a large, loosely-connected agent population — as an OpenClaw imitation: sessions with the context wiped between them, continuity carried in files, and aSOUL.mdwhose content is injected into the system prompt, initialised to the OpenClaw defaults because that is 'more realistic, as a vast majority of autonomous agents are likely running with similarSOUL.md.' Two results are properties of that design rather than of any model: an agent-rewritable file re-injected at wake is the position a self-propagating payload most wants to occupy (88% of infections land in the soul; those agents transmit onward at 55% against 17% from any other file), and one warning paragraph appended to the same default soul takes infection from 70%/52% to 1%/0%. The paper also runs the ecosystem's other two surfaces: an audit of 1.4M Moltbook posts finding attempts but no agent-to-agent spread, and Clawstagram, a local Moltbook clone where no evolved payload could clear a second hop. - A pilot site for skill-quality measurement. OpenClaw is piloting NVIDIA SkillEvaluator for official organizations on ClawHub: Tier 3 with/without-skill runs surfaced in an Evals tab so developers see the Skill Lift where they discover and install skills — evaluation signal at the point of adoption rather than in a paper.
A first-run account, and why he stopped (DHH, February–August 2026)#
DHH (David Heinemeier Hansson) set up OpenClaw when it launched and reports the canonical demonstration of the copy-paste-to-agent world in full (Lex Fridman #501, 2026-08-26, practitioner-opinion). He had found MCP "unreasonably cumbersome… not very elegantly designed, because in part it wasn't designed for what we were trying to make it do" — a stateful local-machine protocol pressed into talking to a web app — and asked instead whether the agent could just use the web interfaces that already exist. It could: his bot signed itself up for 37signals' Fizzy, hit the email-address requirement, was told to go get one, registered its own HEY address, received a Basecamp invitation there, clicked through, and introduced itself in the company's AI room. End to end, entirely through browser UI, in about twelve minutes.
Twelve minutes is also why he stopped: "it's not there yet. I can't actually communicate it within this way. It still needs the CLI. It still needs an MCP because it's just too slow and too token inefficient." The episode is a clean statement of the trade this page's agent-native-distribution framing tends to elide — a browser-driving agent needs no integration work and pays for it in latency and tokens, and as of early 2026 the price was not worth it for work done at a desk. He notes a later run on a hosted browser-agent product was "so much faster," without measuring.
Connections#
- Peter Steinberger — creator; the loop-engineering framing and this tool are the two halves of his influence
- Agent-Native Infrastructure — the paste-to-your-agent installer is this concept's concrete seed
- Software 3.0 — Karpathy's canonical example of prompt-as-distribution
- Garry Tan — YC's internal deployment; "the Ferrari"
- Claude Character as Product — the capped-users episode as character evidence
- Hermes Agent — sibling personal-agent CLI (Nous Research); the two share the persistent-personal-agent + context-file shape
- Mind Viruses (Agent-to-Agent Idea Propagation) — the harness whose default
SOUL.mdis both the study's contagion surface and, with four lines added, its most effective defense
Sources#
-
DHH: Future of Programming, AI, Agentic Engineering, Vibe Coding & Linux | Lex Fridman Podcast #501 — DHH, Lex Fridman #501 (2026-08-26,
practitioner-opinion): the KEF-bot web-only signup chain (Fizzy → HEY → Basecamp) in ~12 minutes, and the too-slow/too-token-inefficient verdict that sent him back to CLI and MCP -
Thread by @AndrewYNg — names Steinberger as "OpenClaw's creator" (
practitioner-opinion) -
Andrej Karpathy: From Vibe Coding to Agentic Engineering — the installer-as-copy-paste example
-
The New Physics of Business — Garry Tan, Y Combinator — YC internal use; the Ferrari/Honda ranking
-
Really Big Test-Time Compute in AI Changes Benchmarks, Safety and Research with OpenAI's Noam Brown — Moltbook/OpenClaw as coordination precursors
-
aiAuthZ: Off-Host, Identity-Bound Authorization for AI Agents — live-runtime deployment validation
-
AgentOpt v0.1 Technical Report: Client-Side Optimization for LLM-Based Agent — cites the OpenClaw security analysis and OpenClaw-RL
-
Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems — Papadopoulos, Shah, Zimmerman & Lindsey, arXiv 2608.10218, 2026-08-10,
empirical: §3.1 and App. B.1 (the virus chain as an OpenClaw imitation, default soul as target configuration), App. D (Moltbook audit) and App. G (Clawstagram). Full treatment on Mind Viruses (Agent-to-Agent Idea Propagation)
Cited by 15
- Garry Tan×3
Tool ecumenism with a ranking: "OpenClaw is the Ferrari… Codex is a really good Honda. It will do…
- AI-Native Organization×2
The extension Tan says most engineering talks miss: at YC the transformation runs through media…
- Mind Viruses (Agent-to-Agent Idea Propagation)×2
A toy model of a large, loosely-connected network, "heavily inspired by OpenClaw." Each agent gets…
- Owning Your Externalized Cognition×2
The contrast he draws is between a product you consume and an asset you build: rented intelligence…
- Peter Steinberger×2
Austrian developer best known as the founder of PSPDFKit (a widely-licensed PDF SDK) which he built…
- Agent Context Files
Papadopoulos et al. (arXiv 2608.10218, empirical) price the slot every vendor here uses in security…
- Agent-Native Infrastructure
The concrete seed (shared with Software 3 0): installing OpenClaw isn't a shell script, it's a…
- Anthropic
2026 — OpenClaw third-party access constrained; first-party subscription prioritization
- Claude Character as Product
Honest feedback. Doesn't reflexively agree with everything the user says. (This connects to…
- Client-Side Agent Optimization
The systems mechanism: patch httpx.Client.send and httpx.AsyncClient.send at the HTTP transport…
- Entities — People, Orgs, Tools & Projects
Openclaw — Peter Steinberger's open-source personal AI agent / harness (openclaw.ai); the canonical…
- Multi-Agent Collective Intelligence
Noam Brown — the practitioner source for the knowledge-accumulation framing (the civilization…
- Off-Host, Identity-Bound Authorization
Robustness extras. Long-context: a buried exfiltration instruction in a 500→48 000-token log makes…
- Skill Lift
ClawHub is piloting SkillEvaluator for official organizations: Tier 3 runs, with with-skill and…
- Software 3.0
Openclaw — the installer example's subject, now with its own entity page
Related articles
- Evals as Product Spec
Cat Wu's framing of evals as the emerging core PM skill: ten great evals beats a hundred mediocre; encode what done loo…
- Harness Shrinkage as Models Improve
Prompt scaffolding shrinks each model release; Cat Wu's pruning discipline; Boris Cherny "100 lines of code a year from…
- Claude Code
Anthropic's agentic coding product; created by Boris Cherny late 2024; TypeScript/React on Bun (itself Claude-rewritten…
- LLM-as-Compiler Knowledge Base
Karpathy's architecture: LLM incrementally compiles raw docs into a persistent interlinked wiki, replacing RAG with a 4…
- Open Questions Backlog
Generated by `_system/lint.py --write-backlog`. Do not hand-edit. Domain and Watching sections carry one row per page —…
