General-purpose agent

OpenClaw

Always-on personal agent harness with coding tools, durable automation, and broad model choice.

Status
Active
License
MIT
Evidence
Documented + code-verifiable, 30 sources
Product record checked
2026-07-28

At a glance

An MIT-licensed general-purpose agent harness with an embedded model-and-tool loop, repository-capable file and shell tools, persistent memory and compaction, nested subagents, multi-agent routing, browser and MCP integrations, durable background automation, and optional container isolation.

Good choice if

  • Always-on personal automation that also needs to inspect, edit, and execute code in a workspace
  • Self-hosted workflows spanning provider APIs, subscriptions, local models, browser control, MCP, and messaging channels
  • Persistent scheduled work and parallel delegation managed through one gateway, task ledger, and session system

Check before choosing

  • It is a broad personal-agent platform rather than a coding-only CLI, so onboarding, operational responsibility, and attack surface are larger than for a focused repository assistant
  • The normal runtime is host-first and sandboxing is off by default; the coding tool profile controls tool visibility but is not process isolation
  • File, shell, browser, messaging, skills, plugins, and remote channels cross different trust boundaries; third-party skills and plugins must be treated as executable trusted code
See 4 more considerations
  • The default rolling main session is designed for one trusted user; shared or multi-user deployments require explicit DM isolation, channel allowlists, scoped tools, and separate workspaces
  • Compaction, transcript persistence, task recovery, and restart recovery do not provide repository-file rollback or reverse shell, browser, message, or external-service side effects
  • OpenTelemetry and the enterprise conformance policy are optional; the policy checks configuration drift and does not enforce each tool call at request time
  • Claw-SWE-Bench evaluates OpenClaw through a repository adapter; HarnessMatch records that study as methodology evidence and imports no product score from it

Why it qualifies as a coding harness

This confirms category fit, not product quality. Every required criterion links back to first-party evidence.

Qualifies4 of 4 required criteria evidenced

Membership establishes category fit only. It does not score quality, safety, autonomy, model capability, or benchmark performance. · Read the membership rule.

How it works under the hood

Seven mechanisms mapped from first-party records. These labels describe what the harness provides, not how intelligent its model is.

7/7layers documented
  • Execution & isolationSandbox availableDocumented mechanism, not a performance score.
  • Tooling & integrationsExtensible + browserDocumented mechanism, not a performance score.
  • Context & statePersistent stateDocumented mechanism, not a performance score.
  • Lifecycle & recoveryManaged recoveryDocumented mechanism, not a performance score.
  • ObservabilityStructured tracesDocumented mechanism, not a performance score.
  • VerificationTool-assistedDocumented mechanism, not a performance score.
  • Governance & permissionsPolicy controlsDocumented mechanism, not a performance score.
Ecosystem signal

OpenRouter routing footprint

Public traffic attributed to this app on OpenRouter. The comparable API window runs from 2026-06-28 to 2026-07-27. It is context about one routing channel, not a capability or quality score.

Open app page
30-day coding rank
#4
Coding category
30-day attributed tokens
4.61T
Same API window
30-day attributed requests
86.97M
Same API window

Attribution excludes direct APIs, subscriptions, local models, and traffic without app attribution. OpenRouter coding-category rank is channel-specific; an unlisted app is not scored as zero. Token volume is not a standardized workload, user count, or task-success measure.

OpenRouter setupDataset definitionApp page: 4.77T tokens, 376 models, daily rank #4Source: OpenRouter (openrouter.ai/apps), as of

Public code audit

5/5public artifacts present
Security policy
Present at inspected commit
CI workflow
Present at inspected commit
Automated tests
Present at inspected commit
Evaluation assets
Present at inspected commit
Contributor documentation
Present at inspected commit

The inspected main snapshot declares package 2026.7.2 ahead of the v2026.7.1 GitHub release and contains 9,560 test-like paths, 81 workflows, security and contributor documentation, and a small number of project-owned benchmark or evaluation assets. Engineering tests and project-owned eval assets are not independent product-performance evidence, so no score is imported.

Inspect commit 4ce534aec2e3ab0fefe7eb6b131cc7be5023500d, checked 2026-07-28

Measured configurations

No benchmark run passes the full metadata admission policy for this harness yet. Missing data is not scored as zero.

Benchmark policy and all runs

Capability support

Documented first-class product support, checked against the sources below.

External tools (MCP)
DocumentedProduct-supported MCP integrationSource · checked 2026-07-28The source establishes the mechanism, not its quality or availability in every mode.
Local models
DocumentedLocal or self-hosted model pathSource · checked 2026-07-28The source establishes the mechanism, not its quality or availability in every mode.
Agent parallelism
DocumentedDelegated or parallel agent workflowSource · checked 2026-07-28The source establishes the mechanism, not its quality or availability in every mode.
Runs without an open UI
DocumentedNon-interactive or automation surfaceSource · checked 2026-07-28The source establishes the mechanism, not its quality or availability in every mode.
Browser control
DocumentedBuilt-in or product-supported browser controlSource · checked 2026-07-28The source establishes the mechanism, not its quality or availability in every mode.
Isolated execution
OptionalOptional container isolation when sandboxing is deliberately enabledSource · checked 2026-07-28The normal local runtime remains host-first and unsandboxed by default.
Undo file changes
Not documentedNo first-class support established by the current recordAbsence of current documentation is not proof that the capability is impossible.

Primary evidence

Each capability claim is tied to a first-party record and a verification date.

Product record checked 2026-07-28
View 22 additional sources
Product and interfaces2 sources
Execution and control3 sources
Agents, state and recovery4 sources
Automation and extensions5 sources
Enterprise and operations2 sources
Releases and public code audit6 sources