nanoclawBLOCK
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An AI assistant that runs agents securely in their own containers. Lightweight, built to be easily understood and completely customized for your needs.
nanoclaw.dev • docs • 中文 • 日本語 • 한국어 • •
Agents in Slack: one app per agent
Setup provisions each agent its own Slack app: manifest, avatar, and workspace install, no tokens to paste. Spawn teammates from chat: every one gets its own bot identity, container, and memory, with shared rooms and canvases.
[](#quick-start)
Why I Built NanoClaw
OpenClaw is an impressive project, but I wouldn't have been able to sleep if I had given complex software I didn't understand full access to my life. OpenClaw has nearly half a million lines of code, 53 config files, and 70+ dependencies. Its security is at the application level (allowlists, pairing codes) rather than true OS-level isolation. Everything runs in one Node process with shared memory.
NanoClaw provides that same core functionality, but in a codebase small enough to understand: on
11d7adeee732OBSERVED · 2026-09-30Install
Commands as the repository documents them. They are shown, not run.
npm install -g @microsoft/[email protected] --loglevel=error
git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
git clone https://github.com/nanocoai/nanoclaw.git nanoclaw-v2
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| codex | mentioned | |
| cursor | mentioned | |
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: add-anydoc
description: Add local office-document-to-Markdown conversion to NanoClaw agent containers with the pinned Firecrawl AnyDoc CLI. Use when agents need to read attached Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV, or text-based PDF files without uploading them to a hosted parser.
---
# Add AnyDoc
Install one pinned CLI and one focused container skill. Keep document conversion inside the agent container; do not change NanoClaw's attachment pipeline or add credentials, an MCP server, or a hosted parser.
## Preflight
1. Read `CONTRIBUTING.md`, `docs/skill-guidelines.md`, and the supply-chain section of `docs/SECURITY.md`.
2. Run this check against the official npm registry before changing files:
```bash
curl -fsSL "https://registry.npmjs.org/@firecrawl%2Fanydoc" | node -e '
let body = "";
process.stdin.setEncoding("utf8");
process.stdin.on("data", (chunk) => (body += chunk));
process.stdin.on("end", () => {
const metadata = JSON.parse(body);
const version = "0.1.6";
const release = metadata.versions?.[version];
const publishedAt = Date.parse(metadata.time?.[version] ?? "");
const eligibleAt = publishedAt + 72 * 60 * 60 * 1000;
if (!release) throw new Error(`${version} is missing from the registry`);
if (release.deprecated) throw new Error(`${version} is deprecated: ${release.deprecated}`);
if (!Number.isFinite(publishedAt)) throw new Error(`missing publish time for ${version}`);
if (Date.now() < eligibleAt) throw new Error(`${version} is gated until ${new Date(eligibleAt).toISOString()}`);
console.log(`${version} passed the 72-hour release gate`);
});
'
```
Stop on any failure. Do not install a PR commit, add a `minimumReleaseAgeExclude`, enable lifecycle scripts, or silently substitute another version, unless the user explicitly approves it.
3. Inspect `container/cli-tools.json` for `@firecrawl/anydoc` before changing files:
- No entry: continue.
- Exactly one entry at `0.1.6`: leave it unchanged.
- A duplicate or any other version: stop and report the conflict.
4. Check whether `container/skills/convert-documents-to-markdown/SKILL.md` and `src/anydoc-manifest.test.ts` already exist. Reapplying this skill overwrites only those dedicated files.
5. If `data/v2.db` exists, inspect per-group image pins before changing files. Standard derived images can be rebuilt from the updated shared image. Stop and report any other pin because its owner must decide how to rebuild it:
```bash
if [ -f data/v2.db ]; then
source setup/lib/install-slug.sh
image_base="$(container_image_base)"
foreign=0
while IFS='|' read -r group_id image_tag package_count; do
[ -z "$group_id" ] && continue
if [ "$image_tag" != "${image_base}:${group_id}" ]; then
echo "Foreign image pin: $group_id -> $image_tag" >&2
foreign=1
elif [ "$package_count" -eq 0 ]; then
echo "Derived image cannot be rebuilt: $group_id has no configured packages" >&2
foreign=1
elif ! ncl groups get --id "$group_id" >/dev/null; then
echo "Cannot reach NanoClaw through ncl for derived image: $group_id" >&2
foreign=1
fi
done < <(pnpm exec tsx scripts/q.ts data/v2.db \
"SELECT agent_group_id, image_tag, COALESCE(json_array_length(packages_apt), 0) + COALESCE(json_array_length(packages_npm), 0) FROM container_configs WHERE image_tag IS NOT NULL ORDER BY agent_group_id")
[ "$foreign" -eq 0 ]
fi
```
## Install
Resolve this skill's bundled files from either Claude Code's skill variable or the project skill directory, then copy both files:
```bash
project_root="$(git rev-parse --show-toplevel)"
skill_dir="${CLAUDE_SKILL_DIR:-$project_root/.claude/skills/add-anydoc}"
test -f "$skill_dir/container-skills/convert-documents-to-markdown/SKILL.md"
test -f "$skill_dir/anydoc-manifest.test.ts"
mkdir -p container/skills/convert-documents-to-markdown
cp "$skill_dir/container-skills/convert-documents-to-markdown/SKILL.md" \
container/skills/convert-documents-to-markdown/SKILL.md
cp "$skill_dir/anydoc-manifest.test.ts" src/anydoc-manifest.test.ts
```
If the manifest has no AnyDoc entry, append this exact object to its JSON array. Do not add `onlyBuilt`; the package and its prebuilt Linux bindings have no install lifecycle script.
```json
{ "name": "@firecrawl/anydoc", "version": "0.1.6" }
```
## Validate and build
Run validation before building the image:
```bash
pnpm exec vitest run src/anydoc-manifest.test.ts container/cli-tools.test.ts
pnpm run build
./container/build.sh
```
If pnpm rejects the package as too new, stop. Do not bypass the release-age policy.
Rebuild standard per-group images so groups with custom packages inherit the updated shared image:
```bash
if [ -f data/v2.db ]; then
source setup/lib/install-slug.sh
image_base="$(container_image_base)"
while IFS='|' read -r group_id image_tag; do
[ -z "$group_id" ] && continue
if [ "$image_tag" != "${image_base}:${group_id}" ]; then
echo "Foreign image pin appeared during install: $group_id -> $image_tag" >&2
exit 1
fi
ncl groups restart --id "$group_id" --rebuild
done < <(pnpm exec tsx scripts/q.ts data/v2.db \
"SELECT agent_group_id, image_tag FROM container_configs WHERE image_tag IS NOT NULL ORDER BY agent_group_id")
fi
```
Resolve this install's image name and exercise the native binding, not only the help path:
```bash
source setup/lib/install-slug.sh
image="$(container_image_base):latest"
docker run --rm --entrypoint anydoc "$image" --version
printf 'name,count\nalpha,2\n' | \
docker run --rm -i --entrypoint anydoc "$image" - --format csv | grep -q alpha
docker run --rm --entrypoint sh "$image" -c 'command -v timeout'
```
If `timeout` is absent, remove its wrapper from the installed container skill; do not add another dependency. Convert local DOCX, PPTX, and XLSXTrust audit
BLOCKgrade F · trust 33/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
"github_token": "ghp_fake0123456789fake0123456789fake01",
"bot_token": "xoxb-fake-bot-token",
"bot_token": "xoxb-fake-bot-token",
"bot_token": "xoxb-fake-bot-token",
- **terminology**: Resend handles email. The bot has one fixed sending identity (`RESEND_FROM_ADDRESS`, e.g. `[email protected]`); every *external correspondent* the bot emails with is a separate con
- **how-to-find-id**: The platform ID is the **correspondent's** email address, prefixed — `resend:<their-address>` (e.g. `resend:[email protected]`) — **not** the bot's from-address. The adapter derive
**Replies never reach the agent.** Inbound only flows via the webhook: Resend → **Webhooks** must point at your public host at `/webhook/resend` (shared webhook server, port 3000) with the **email.rec
curl -sf -X POST "https://login.microsoftonline.com/{{app_tenant_id}}/oauth2/v2.0/token" --data-urlencode "grant_type=client_credentials" --data-urlencode "client_id={{app_id}}" --data-urlencode "clieCreate the second Telegram bot: message @BotFather, send /newbot and follow the prompts (its own friendly name, then a username that must end in "bot"), and copy the token it gives you. It must be a d
exec(`${opener} ${url}`, (err) => {await exec(gitFetchBranchCommand(remote, b));
await exec(gitShowToFileCommand(`refs/remotes/${remote}/${b}`, srcOf(l), destOf(l)));'.netrc',
'id_rsa',
'id_ed25519',
'.env' ... curl
The following are read from the process environment (not `.env`). To override them, add `Environment=` lines to the systemd service unit or your launchd plist:
Read the API key from the host auth file — the single source of truth, written
| `src/config.ts` | Process-level config (assistant name, paths, timeouts) read from `.env` |
- **A2A cache staleness.** The a2a room allowlist is re-read from `.env` on a
**Principle:** Do the work — don't tell the user to do it. Only ask for their input when it genuinely requires manual action (pasting a token).
⚠️ **CRITICAL**: If you skip step 2, nothing happens. The agent exists but has no work. You MUST send the message. Do NOT tell the user "it's working on it" until you have actually called send_message
Run commands directly — don't tell the user to run them.
.agents/skills
content.replace(/^MATTERMOST_(?:BASE_URL|BOT_TOKEN|CALLBACK_URL|CALLBACK_SECRET)=.*\n?/gm, ''),
Gates applied: critical_finding, instruction_override, no_behavioural_pass, undeclared_transfer.
11d7adeee732full audit observations/trust-audit/skill/nanocoai__nanoclaw.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 11d7adeee732 | BLOCK | F | 33 | first audit |
Questions
What does the nanoclaw skill do?
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
Is nanoclaw safe to install?
No — not without reading the findings first. The audit graded it F (33/100) and found 23 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What can nanoclaw access on my machine?
The audit observed that it reaches the network, runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: found — see the findings.
Which assistants does nanoclaw work with?
Its documentation mentions claude-code, codex, cursor and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (11d7adeee732), read on 2026-09-30. The repository is watched, and a new audit runs when it changes — this is the first audit.