Sep 19, 2026

NanoClaw Runs Your Personal AI Agent in a Container You Can Message

A 31k-star, deliberately small alternative to OpenClaw: each agent gets its own Docker container, shows up in WhatsApp, Telegram, Slack, and other chat apps, and never holds your raw API keys.

#tutorial#agent-tools#deployment

Personal-assistant agents that live in your chat apps usually mean handing a big, opaque codebase the keys to your accounts. NanoClaw — 31k stars — is a counter-proposal: one process, a handful of files, and every agent sandboxed in its own Linux container.

Why This Skill Matters

The README's motivation section is explicit about what it rejects. OpenClaw, in the author's account, has nearly half a million lines of code, 53 config files, and 70+ dependencies, with security at the application level rather than true OS-level isolation. NanoClaw keeps the core function — an agent you message — and shrinks the trust problem: agents see only explicitly mounted directories, and outbound requests route through OneCLI's Agent Vault, which injects credentials at request time, so agents never hold raw API keys.

Channels install on demand as skills: WhatsApp, Telegram, Discord, Slack, Microsoft Teams, iMessage, Matrix, Google Chat, Webex, Linear, GitHub, WeChat, and email via Resend. Run /add-telegram and the skill copies exactly the module you need into your fork. Customization works the same way — there are no configuration files; you tell Claude Code what to change, or run /customize.

Installation

git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
cd nanoclaw-v2
bash nanoclaw.sh

The script walks a fresh machine to a named agent you can message: it installs Node, pnpm, and Docker if missing, registers your Anthropic credential with OneCLI, builds the agent container, and pairs your first channel — Slack, Telegram, Discord, WhatsApp, iMessage, or a local CLI. If a step fails, it hands off to Claude Code to diagnose and resume from where it broke. Requirements are macOS, Linux, or Windows via WSL2, and Claude Code is needed for /customize, /debug, and the /add-<channel> skills.

Real Workflow: Schedule a Morning Briefing

  1. After setup, message the agent by its trigger word (the default is @Andy) from the channel you paired.
  2. Ask for the recurring task:
@Andy every Monday at 8am, compile news on AI developments from Hacker News and TechCrunch and message me a briefing
  1. Manage it from chat: @Andy list all scheduled tasks across groups, then @Andy pause the Monday briefing task.

The host's 60-second sweep wakes the container when a task is due, and optional script gates keep it asleep when there is no actual work.

Real Workflow: Add a Second Channel or a Different Model

Say /add-telegram for another channel, or /add-opencode for OpenRouter, Google, DeepSeek, and more, or /add-ollama-provider for local open-weight models. Channel adapters live on the repo's channels branch and providers on providers; the skill copies exactly the modules you ask for into your fork. Provider is configurable per agent group, so different agents can run on different backends in one install.

Tips

  • There is no monitoring dashboard — debugging is "ask Claude Code": "Why isn't the scheduler running?" is the supported path.
  • NanoClaw needs no user account on the default path. It reports only anonymous setup diagnostics, and NANOCLAW_NO_DIAGNOSTICS=1 turns even those off.
  • Uninstall surgically with bash nanoclaw.sh --uninstall; it asks for confirmation per agent group and offers --dry-run.
  • The whole architecture is one line in the README: messaging apps, host process, inbound database, container (Bun, Claude Agent SDK), outbound database, delivery.

When Not to Use This

Native Windows is not supported (WSL2 only) and Docker is required, so this is not a zero-dependency install. It is also a messaging-first personal-assistant runtime, not an editor-side coding agent. And the bespoke philosophy cuts both ways: customization means code changes in your own fork, which you maintain.


See the leaderboard for more skills.