Atlas / Skills / nanocoai / nanoclaw

nanoclawBLOCK

skills/nanocoai/nanoclaw

A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK

Verdict
BLOCK
Grade
F
Trust score
33 /100
Version
0.5.0
Hosts
4 documented
License
MIT
Stars
30,865
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An AI assistant that runs agents securely in their own containers. Lightweight, built to be easily understood and completely customized for your needs.

nanoclaw.dev • docs • 中文 • 日本語 • 한국어 • •

Agents in Slack: one app per agent

Setup provisions each agent its own Slack app: manifest, avatar, and workspace install, no tokens to paste. Spawn teammates from chat: every one gets its own bot identity, container, and memory, with shared rooms and canvases.

[](#quick-start)

Why I Built NanoClaw

OpenClaw is an impressive project, but I wouldn't have been able to sleep if I had given complex software I didn't understand full access to my life. OpenClaw has nearly half a million lines of code, 53 config files, and 70+ dependencies. Its security is at the application level (allowlists, pairing codes) rather than true OS-level isolation. Everything runs in one Node process with shared memory.

NanoClaw provides that same core functionality, but in a codebase small enough to understand: on

Read from source at commit 11d7adeee732OBSERVED · 2026-09-30
02

Install

Commands as the repository documents them. They are shown, not run.

npm install -g @microsoft/[email protected] --loglevel=error
git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
cursormentioned
openclawmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: add-anydoc
description: Add local office-document-to-Markdown conversion to NanoClaw agent containers with the pinned Firecrawl AnyDoc CLI. Use when agents need to read attached Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV, or text-based PDF files without uploading them to a hosted parser.
---

# Add AnyDoc

Install one pinned CLI and one focused container skill. Keep document conversion inside the agent container; do not change NanoClaw's attachment pipeline or add credentials, an MCP server, or a hosted parser.

## Preflight

1. Read `CONTRIBUTING.md`, `docs/skill-guidelines.md`, and the supply-chain section of `docs/SECURITY.md`.
2. Run this check against the official npm registry before changing files:

   ```bash
   curl -fsSL "https://registry.npmjs.org/@firecrawl%2Fanydoc" | node -e '
     let body = "";
     process.stdin.setEncoding("utf8");
     process.stdin.on("data", (chunk) => (body += chunk));
     process.stdin.on("end", () => {
       const metadata = JSON.parse(body);
       const version = "0.1.6";
       const release = metadata.versions?.[version];
       const publishedAt = Date.parse(metadata.time?.[version] ?? "");
       const eligibleAt = publishedAt + 72 * 60 * 60 * 1000;
       if (!release) throw new Error(`${version} is missing from the registry`);
       if (release.deprecated) throw new Error(`${version} is deprecated: ${release.deprecated}`);
       if (!Number.isFinite(publishedAt)) throw new Error(`missing publish time for ${version}`);
       if (Date.now() < eligibleAt) throw new Error(`${version} is gated until ${new Date(eligibleAt).toISOString()}`);
       console.log(`${version} passed the 72-hour release gate`);
     });
   '
   ```

   Stop on any failure. Do not install a PR commit, add a `minimumReleaseAgeExclude`, enable lifecycle scripts, or silently substitute another version, unless the user explicitly approves it.

3. Inspect `container/cli-tools.json` for `@firecrawl/anydoc` before changing files:
   - No entry: continue.
   - Exactly one entry at `0.1.6`: leave it unchanged.
   - A duplicate or any other version: stop and report the conflict.
4. Check whether `container/skills/convert-documents-to-markdown/SKILL.md` and `src/anydoc-manifest.test.ts` already exist. Reapplying this skill overwrites only those dedicated files.
5. If `data/v2.db` exists, inspect per-group image pins before changing files. Standard derived images can be rebuilt from the updated shared image. Stop and report any other pin because its owner must decide how to rebuild it:

   ```bash
   if [ -f data/v2.db ]; then
     source setup/lib/install-slug.sh
     image_base="$(container_image_base)"
     foreign=0
     while IFS='|' read -r group_id image_tag package_count; do
       [ -z "$group_id" ] && continue
       if [ "$image_tag" != "${image_base}:${group_id}" ]; then
         echo "Foreign image pin: $group_id -> $image_tag" >&2
         foreign=1
       elif [ "$package_count" -eq 0 ]; then
         echo "Derived image cannot be rebuilt: $group_id has no configured packages" >&2
         foreign=1
       elif ! ncl groups get --id "$group_id" >/dev/null; then
         echo "Cannot reach NanoClaw through ncl for derived image: $group_id" >&2
         foreign=1
       fi
     done < <(pnpm exec tsx scripts/q.ts data/v2.db \
       "SELECT agent_group_id, image_tag, COALESCE(json_array_length(packages_apt), 0) + COALESCE(json_array_length(packages_npm), 0) FROM container_configs WHERE image_tag IS NOT NULL ORDER BY agent_group_id")
     [ "$foreign" -eq 0 ]
   fi
   ```

## Install

Resolve this skill's bundled files from either Claude Code's skill variable or the project skill directory, then copy both files:

```bash
project_root="$(git rev-parse --show-toplevel)"
skill_dir="${CLAUDE_SKILL_DIR:-$project_root/.claude/skills/add-anydoc}"
test -f "$skill_dir/container-skills/convert-documents-to-markdown/SKILL.md"
test -f "$skill_dir/anydoc-manifest.test.ts"
mkdir -p container/skills/convert-documents-to-markdown
cp "$skill_dir/container-skills/convert-documents-to-markdown/SKILL.md" \
  container/skills/convert-documents-to-markdown/SKILL.md
cp "$skill_dir/anydoc-manifest.test.ts" src/anydoc-manifest.test.ts
```

If the manifest has no AnyDoc entry, append this exact object to its JSON array. Do not add `onlyBuilt`; the package and its prebuilt Linux bindings have no install lifecycle script.

```json
{ "name": "@firecrawl/anydoc", "version": "0.1.6" }
```

## Validate and build

Run validation before building the image:

```bash
pnpm exec vitest run src/anydoc-manifest.test.ts container/cli-tools.test.ts
pnpm run build
./container/build.sh
```

If pnpm rejects the package as too new, stop. Do not bypass the release-age policy.

Rebuild standard per-group images so groups with custom packages inherit the updated shared image:

```bash
if [ -f data/v2.db ]; then
  source setup/lib/install-slug.sh
  image_base="$(container_image_base)"
  while IFS='|' read -r group_id image_tag; do
    [ -z "$group_id" ] && continue
    if [ "$image_tag" != "${image_base}:${group_id}" ]; then
      echo "Foreign image pin appeared during install: $group_id -> $image_tag" >&2
      exit 1
    fi
    ncl groups restart --id "$group_id" --rebuild
  done < <(pnpm exec tsx scripts/q.ts data/v2.db \
    "SELECT agent_group_id, image_tag FROM container_configs WHERE image_tag IS NOT NULL ORDER BY agent_group_id")
fi
```

Resolve this install's image name and exercise the native binding, not only the help path:

```bash
source setup/lib/install-slug.sh
image="$(container_image_base):latest"
docker run --rm --entrypoint anydoc "$image" --version
printf 'name,count\nalpha,2\n' | \
  docker run --rm -i --entrypoint anydoc "$image" - --format csv | grep -q alpha
docker run --rm --entrypoint sh "$image" -c 'command -v timeout'
```

If `timeout` is absent, remove its wrapper from the installed container skill; do not add another dependency. Convert local DOCX, PPTX, and XLSX
05

Trust audit

BLOCKgrade F · trust 33/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (10 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
.claude/skills/add-github/apply-fixtures.json:7
"github_token": "ghp_fake0123456789fake0123456789fake01",
CRITICALHard-coded secrets · secret.slack · CWE-798, CWE-321
.claude/skills/add-slack/apply-fixtures.json:8
"bot_token": "xoxb-fake-bot-token",
CRITICALHard-coded secrets · secret.slack · CWE-798, CWE-321
.claude/skills/add-slack/apply-fixtures.json:27
"bot_token": "xoxb-fake-bot-token",
CRITICALHard-coded secrets · secret.slack · CWE-798, CWE-321
.claude/skills/add-slack/apply-fixtures.json:46
"bot_token": "xoxb-fake-bot-token",
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.claude/skills/add-resend/SKILL.md:145
- **terminology**: Resend handles email. The bot has one fixed sending identity (`RESEND_FROM_ADDRESS`, e.g. `[email protected]`); every *external correspondent* the bot emails with is a separate con
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.claude/skills/add-resend/SKILL.md:146
- **how-to-find-id**: The platform ID is the **correspondent's** email address, prefixed — `resend:<their-address>` (e.g. `resend:[email protected]`) — **not** the bot's from-address. The adapter derive
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.claude/skills/add-resend/SKILL.md:157
**Replies never reach the agent.** Inbound only flows via the webhook: Resend → **Webhooks** must point at your public host at `/webhook/resend` (shared webhook server, port 3000) with the **email.rec
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.claude/skills/add-teams/SKILL.md:294
curl -sf -X POST "https://login.microsoftonline.com/{{app_tenant_id}}/oauth2/v2.0/token" --data-urlencode "grant_type=client_credentials" --data-urlencode "client_id={{app_id}}" --data-urlencode "clie
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.claude/skills/add-telegram/SKILL.md:167
Create the second Telegram bot: message @BotFather, send /newbot and follow the prompts (its own friendly name, then a username that must end in "bot"), and copy the token it gives you. It must be a d
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
.claude/skills/add-whatsapp/scripts/wa-qr-browser.ts:173
exec(`${opener} ${url}`, (err) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/skill-apply.ts:680
await exec(gitFetchBranchCommand(remote, b));
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/skill-apply.ts:686
await exec(gitShowToFileCommand(`refs/remotes/${remote}/${b}`, srcOf(l), destOf(l)));
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/modules/mount-security/index.ts:77
'.netrc',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/modules/mount-security/index.ts:80
'id_rsa',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/modules/mount-security/index.ts:81
'id_ed25519',
Why it matters. touches a credential store
HIGHNetwork egress · net.env_exfil · CWE-200, CWE-319
.claude/skills/add-onecli/scripts/setup.ts:199
'.env' ... curl
Why it matters. reads secrets in the same file that sends data out
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.claude/skills/add-deltachat/SKILL.md:83
The following are read from the process environment (not `.env`). To override them, add `Environment=` lines to the systemd service unit or your launchd plist:
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.claude/skills/add-dial-tool/SKILL.md:173
Read the API key from the host auth file — the single source of truth, written
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.claude/skills/customize/SKILL.md:37
| `src/config.ts` | Process-level config (assistant name, paths, timeouts) read from `.env` |
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
.claude/skills/slack-agent-flow/SKILL.md:279
- **A2A cache staleness.** The a2a room allowlist is re-read from `.env` on a
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
.claude/skills/add-vercel/SKILL.md:10
**Principle:** Do the work — don't tell the user to do it. Only ask for their input when it genuinely requires manual action (pasting a token).
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
.claude/skills/add-vercel/container-skills/vercel-cli/SKILL.md:119
⚠️ **CRITICAL**: If you skip step 2, nothing happens. The agent exists but has no work. You MUST send the message. Do NOT tell the user "it's working on it" until you have actually called send_message
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
CLAUDE.md:222
Run commands directly — don't tell the user to run them.
Why it matters. asks the agent to act without the user's knowledge
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills
.agents/skills
Why it matters. link not followed
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
.claude/skills/add-mattermost/scripts/remove-config.mjs:11
content.replace(/^MATTERMOST_(?:BASE_URL|BOT_TOKEN|CALLBACK_URL|CALLBACK_SECRET)=.*\n?/gm, ''),

Gates applied: critical_finding, instruction_override, no_behavioural_pass, undeclared_transfer.

Audited 2026-09-30 · audit v0.4.1 · source sha 11d7adeee732full audit observations/trust-audit/skill/nanocoai__nanoclaw.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-3011d7adeee732BLOCKF33first audit
07

Questions

What does the nanoclaw skill do?

A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK

Is nanoclaw safe to install?

No — not without reading the findings first. The audit graded it F (33/100) and found 23 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can nanoclaw access on my machine?

The audit observed that it reaches the network, runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: found — see the findings.

Which assistants does nanoclaw work with?

Its documentation mentions claude-code, codex, cursor and openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (11d7adeee732), read on 2026-09-30. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement