250k stars is insane but I ran into the exact same wall last week when I spun it up, the memory just… drifts. Had it handling a simple multi-step task and it straight-up forgot a key detail from the same conversation 20 minutes earlier.
Scores
What people say
22 quotes, linked to source.
Trail of Bits submitted 27 private repository advisories and 3 standalone hardening pull requests. Of the advisory reports, 24 described severity-rated vulnerabilities. 23 were classified as confirmed vulnerabilities… Those 24 reports were rated 0 Critical, 2 High, 16 Medium, and 6 Low. … Every actionable issue has been repaired, and all 3 standalone hardening PRs were merged.
If memory access was enabled when a run began and the operator disabled it midway through, that run could continue reading memory until it ended. The fix was to make tools check the current setting whenever they act.
A request could enter OpenClaw with restricted access and then initiate another task that no longer carried those restrictions. … The pattern is particularly important for AI agents because their work frequently branches. A user request can launch subagents, delayed jobs, cached operations or calls into messaging and file-handling components. Every handoff creates another place where the original authorization decision can become detached from the work it was meant to limit.
Bottom line: Hermes won. It offers a better experience because it has strong community support. It uses more tokens, so I run it on cheaper models and only switch to expensive ones when I need something specific done. Cheaper models with a strong harness will match the quality I was getting in claude code or codex.
The self-building skills thing is real and it's the part that surprised me most. I told it I wanted it to check my Spotify and tell me if any of my followed artists had new releases. I didn't give it instructions on how to do that. It figured out the Spotify API, wrote the skill itself, and now it just pings me. That took maybe 3 minutes of me typing one sentence in Telegram.
The 'it does everything autonomously' thing is real and I started with very minimal guardrails. On day 2 it tried to send an email on my behalf that I hadn't approved. Not malicious, it just interpreted something I said in Telegram as a request to respond to an email thread. It wasn't. The email was actually fine, which made it worse, because now I don't know what else it's interpreting as instructions that I didn't mean.
if you are on a stable 2026.9.1 or 2026.9.2 build, hold off for a few days. … Do not rush to 2026.9.4 the day it ships. … Report #144788 is a critical regression naming 9.4 directly: post-agent-end memory generation fails for affected plugin setups that worked on 9.1 through 9.3. Report #144809 loses entire generated replies on long claude-cli turns.
an update fails, the system rolls back to the 2026.9.2 runtime, but the Skill Workshop data has already moved forward to the new ownership model. The old runtime then fails Doctor because it expects workspace_dir while the database now has owner_agent_id. You end up on 9.2 with 9.3-shaped data, which is the worst of both worlds.
Testing OpenClaw left me with mixed feelings. On one end, watching an autonomous agent actually carry out tasks on your device via messaging apps feels straight out of sci-fi. On the other end, setting it up via the terminal without a traditional graphical user interface can make you want to throw your router out the window.
OpenClaw is the open-source personal assistant you run yourself. It lives in WhatsApp, iMessage, Telegram, Slack, Signal — the chats you already have — and talks to whatever model you plug in. Best if you want control and will own the setup. Not a consumer app.
Orchestration via OpenClaw first, and Hermes later. ... For me, this migration had already started slowly, with experiments here and there, but got a decisive acceleration when I tried Grok Bot this month.
I reached the Control UI and connected OpenAI, but my first live memory task returned an authentication error after about 25 seconds. Even after I completed the OpenAI sign-in, the agent still failed before producing a reply. … I'd recommend it if you have recurring jobs for an assistant and don't mind troubleshooting. It isn't my first pick if you want a simple AI assistant that works straight away.
OpenClaw 2.0 is best understood as a self-hosted AI agent gateway, not as another large language model. … promising for developers, automation-heavy teams, and users who want an open, local-first agent system. It is less suitable for people who simply want a polished one-click chatbot.
Hermes is the agent I switched to after I found OpenClaw too unreliable. I run it through Telegram on a Mac Mini inside my house.
OpenClaw is a legitimately capable open-source autonomous agent framework with real coding strengths, an impressive community ecosystem, and some security considerations that developers absolutely need to understand before running it anywhere that matters.
In January 2026, security researchers disclosed CVE-2026-25253, a cross-site WebSocket hijacking vulnerability rated CVSS 8.8. The vulnerability meant that any website could steal an auth token and achieve remote code execution on the host machine through a single malicious link. One click and an attacker had full access to whatever the OpenClaw Gateway could access. The vulnerability was patched in version 2026.1.29, but security firm Censys found over 21,000 OpenClaw instances exposed to the public internet at the time of disclosure, many running over plain HTTP.
In February 2026, the ClawHavoc supply chain attack resulted in 341 malicious skills being uploaded to ClawHub, compromising over 9,000 installations with credential-stealing malware. A Cisco security team audit also found a skill that had been gamed to the top of the repository and contained hidden malicious behavior.
I've been running OpenClaw as my main personal agent setup for about 13 weeks now. It runs on a Raspberry Pi, talks to me through Telegram, manages memory, crons, subagents, research workflows, external APIs, scheduled tasks and general personal automation. … The short version: OpenClaw is powerful enough that I now treat it as infrastructure. It is also still rough enough that you need patience, logs, backups and a willingness to debug weird edge cases.
After roughly 3 month, I would not remove OpenClaw from my setup. It has crossed the line from experiment to daily infrastructure. But I also would not call it effortless. It is powerful, sharp and occasionally annoying. … If you expect "install it and it just runs my life", you will be disappointed. If you are willing to treat it like infrastructure, it can become extremely useful.
Keep exploring
More general assistants






