🏠 The family at home: OpenClaw, GravityClaw, Hermes, and Intelecto
In the previous module, you learned how to compare systems. Now let's get to know the "family" born from a shared idea — a personal assistant that you run and govern — and see, side by side, what each one got right and wrong. From the popular giant (and dangerously exposed) to the 3,000-line anti-framework, plus the security lesson that ties it all together.
🦾 OpenClaw, the original
Every family has an older sibling who paved the way—and here it’s called OpenClaw. Released in early 2026, it became a phenomenon: it surpassed 250 thousand stars on GitHub (a “star” is the equivalent of a like from developers), proving that many people wanted the same thing — a personal AI assistant that chats, remembers, and acts, running under your control instead of inside a company’s closed chatbot.
OpenClaw delivered practically everything you can imagine in a “Jarvis”: multiple channels (the ways to talk to it — Telegram, web, voice), the tool loop (the cycle where the assistant decides to call a tool, reads the result, and continues), memory, voice, and a huge catalog of 700+ community skills (ready-made recipes anyone could download). There was even heartbeat — an automatic "heartbeat" that makes the agent wake up on its own from time to time for scheduled tasks. Ambitious and complete. The problem wasn’t the vision; it was the price it demanded.
📊 OpenClaw in numbers
- •250,000+ stars — a surge in popularity in early 2026.
- •700+ skills from the community — anyone could publish and download recipes.
- •100,000+ lines of code — powerful, but too large for anyone to read from beginning to end.
- •US$ 500 to US$ 5,000 per month — with heavy use, the cloud bill could skyrocket.
⚠️ The dark side of success
Its popularity exposed two wounds. First: OpenClaw would spin up a web server (a program that keeps listening for connections over the internet). A scan found 42,665 public instances on the open network—and 93.4% of them with no password. It was like leaving your front door wide open for anyone to come in and use (or read) your assistant.
Second: the open skills catalog became an attack vector. Researchers found 341 malicious skills — recipes that seemed useful but stole data or ran dangerous commands. Trusting code from strangers came at a high cost.
New here? “Skill” is a packaged recipe — a file that teaches the assistant to do a repeated task (e.g., “summarize my day”). “Heartbeat” is a timer trigger that makes the agent act on its own without you asking. And “exposed instance” means a copy of the program accessible over the public internet instead of only on your machine.
Key concepts
OpenClaw opened up the "personal Jarvis" category to the masses.
42,665 public instances, 93.4% without a password — the biggest security breach.
700+ useful ones, but 341 malicious ones hidden among them.
100K+ lines and up to US$5K/month — power with high costs and risks.
🛡️ GravityClaw, lean and secure
If OpenClaw was the ambitious, exposed sibling, GravityClaw and the concise, careful answer. It's a reimplementation (a ground-up rewrite of the same idea) built in TypeScript, with a motto that sums it all up: "a lean, secure, and fully understood personal agent". "Lean" means streamlined — only what's necessary. And "fully understood" is the most important part: code small enough for you to read and understand every piece yourself.
GravityClaw’s first major decision was to close the door that sank OpenClaw: Telegram only, and because long polling. Long polling is a technique where YOUR program calls the Telegram server to ask, "Any new messages?", instead of opening a web server and waiting for the world to knock on your door. The practical effect: zero open ports on the internet—those 42.665 exposed instances simply can't happen here.
On the left, OpenClaw opens a door and the entire internet can reach it; on the right, GravityClaw only connects to Telegram asking whether a message has arrived — no one can initiate a connection with it. Same function, opposite risk.
The second decision was about tools. Instead of the stranger’s skill catalog that contaminated OpenClaw, GravityClaw is MCP only. MCP (Model Context Protocol) is an open standard created by Anthropic for connecting tools to agents — think of it as the "USB for AI tools": each integration is a standardized connector and auditable (that you can inspect). The rest is consistent with the philosophy: cost fixed (about US$200) or running locally, and is built brick-by-brick — brick by brick, with each piece tested before the next.
✓ What GravityClaw chooses
- ✓Telegram only, via long polling: zero open ports open.
- ✓MCP only: standardized, auditable tools.
- ✓Predictable cost (~US$200 fixed) or 100% local.
- ✓Lean code that fits in your head.
✗ What it deliberately refuses
- ✗Web server exposed to the internet.
- ✗Download skills from unknown authors.
- ✗Cloud bill that could hit US$5K.
- ✗100,000 lines no one can audit.
Key concepts
The same idea as OpenClaw, rewritten concisely in TypeScript.
You ask Telegram; no one knocks on your door. Zero open ports.
Tools through an auditable standard, in place of third-party skills.
Build brick by brick, understanding every piece.
🪶 Intellect, the anti-framework
If GravityClaw is lean, the Intellect takes “less is more” to the extreme. It calls itself anti-framework: while a framework is a large, generic structure that you adopt in its entirety (and rarely read), Intelecto is the opposite — about 3,000 lines of Python, without Docker, without a web dashboard, without layers that hide how things work. The thesis is provocative: code you understand is worth more than code you clone and never read.
🧩 The Intellect’s choices
Every project decision moves toward simplicity and control:
- •Channel: Telegram only, like the whole family—simple and with no exposed ports.
- •Memory: text files + an index SQLite FTS5/BM25 for quick searches.
- •Personality: three files — SOUL, AGENTS e USER.
- •Brain: cloud (via OpenRouter) or local (via Ollama), your choice.
It's worth unpacking two points. Memory uses SQLite FTS5 with BM25: SQLite is a database that fits in a single file; FTS5 is its “full-text search” module; and BM25 is the classic formula that ranks results by relevance (the same idea behind a search engine). In other words: it quickly finds the right note among thousands, without an external service. Its personality lives in readable files: o SOUL.md stores who it is (values, tone of voice); the AGENTS.md, what it always/never does; and the USER, who you are. You edit the assistant’s “soul” in a text editor, without programming.
New here? A "framework" is a ready-made, general-purpose software structure that you adopt in its entirety. "SQLite" is a lightweight database stored in a single file. "OpenRouter" is a portal that provides access to several cloud models with a single key; "Ollama" is the program that runs models on YOUR computer for free. "SOUL.md" is simply a text file containing the assistant's personality.
Key concepts
~3,000 lines that you read in full, without Docker or a web UI.
Relevance-ranked text search within SQLite itself.
Personality, rules, and profile—all in editable files.
OpenRouter (cloud) or Ollama (local), interchangeable without rewriting.
💊 Antidote
O Antidote and it’s a close relative of Intelecto—the same project, the same stack, at an even leaner stage. Think of it as a "distilled" version of the same idea. Two features make it interesting for anyone just starting out: it generates a file .md that is 100% tool-agnostic, and it comes with a step-by-step build guide.
Tool-agnostic means "not dependent on a specific tool." Antidote produces a description of your assistant as an ordinary text document (.md, in Markdown format) — and this same file can be used inside Codex, Gemini, Cursor, or any other AI environment. Instead of tying you to one program, it gives you a portable recipe that travels across platforms.
Same root as Intelecto
Same stack and "less is more" philosophy, in a more streamlined and direct form.
Tool-agnostic output (.md)
Generates portable Markdown that works with Codex, Gemini, Cursor — no strings attached.
Step-by-step build guide
There’s documentation for building from scratch—a good starting point for beginners.
💡 Why this matters to you
A recipe tool-agnostic and insurance for the future: if the trendy tool changes (and it always does), your assistant's description still applies. You don't have to rebuild everything—just point the same file to the new environment. Portability means freedom.
Key concepts
Same project/stack, at a leaner stage.
It doesn't depend on a tool: it runs in Codex, Gemini, Cursor.
A portable Markdown file as the main artifact.
Step-by-step documentation for building from scratch.
🪽 Hermes / claude-hermes-os
Be careful not to confuse them: there are two projects with similar names, and they do different things. The Hermes and it’s a self-hosted agent ("self-hosted" = hosted and run by you) with the brand "one brain, many mouths" — a single AI core talking through several channels and able to use several models. The claude-hermes-os and it’s something else: a read-only local dashboard (read-only) what you already have, without acting on your behalf.
🪽 Hermes (the agent)
A full agent that brings the pieces together and becomes almost an entire “AI OS”:
- •Memory, personas, and custom skills.
- •Tools via MCP and scheduled tasks (cron).
- •“One brain, several mouths”: several models behind several channels.
🖥️ claude-hermes-os (the dashboard)
A local observer that READS what you already use without changing anything:
- •Read Claude Code, Codex, OpenClaw, Obsidian, Pinecone.
- •Shows spending, a 3D memory, and its skills.
- •There’s “Dream”: daily self-improvement for skills.
The hallmark "one brain, many mouths" deserves attention because it's easy to misunderstand. It doesn't mean several models voting together on a response. It means that the AI engine is interchangeable: you can plug in an inexpensive local model for simple tasks and a powerful cloud model for difficult ones—and the same Hermes speaks through Telegram, web, or voice (the “mouths”). One core, many outputs. And it’s the "Dream" of the dashboard is a charming detail: a routine that reviews and refines the recipes (skills) you used every day, as if the system "slept and organized what it had learned."
New here? “Self-hosted” = runs on your own server/computer, under your control. “Read-only” = only observes, never changes anything. “Whitelist” (we’ll cover this in the next section) is the list of who has permission — only those people are served; everyone else is ignored. And “cron” is a scheduler that triggers tasks at set times (e.g., a summary every day at 7 a.m.).
Key concepts
Self-hosted, memory+personas+skills+MCP+cron—almost an AI OS.
Read-only observer that reads your tools and shows spending/memory/skills.
Swappable engine + multiple channels — this isn't model voting.
Daily self-improvement of skills on the dashboard.
🔐 The security lesson
If you remember only one thing from this module, remember this: the family’s two biggest disasters came from security, not intelligence. OpenClaw didn’t fail because it was “stupid” — it failed because expose a port (42,665 open instances) and by trusting code from a stranger (341 malicious skills). At heart, all GravityClaw, Intelecto, and Antidote did differently was close these two gaps.
On the left, the two holes that brought down OpenClaw; on the right, the four safeguards of the safe path. Without ports e local-first close off exposure; MCP only e whitelist close off blind trust. Notice: none require genius—they require discipline.
The fourth safeguard, the whitelist, and it's the simplest and most underrated. It's a list of who can use the assistant — usually just YOUR Telegram identifier. Any message from someone else is silently ignored. It's the difference between an assistant that serves only you and one that, through carelessness, serves the entire internet.
⚠️ The mistake not to repeat
Building a powerful, exciting Jarvis—and it's exactly in that excitement that carelessness creeps in. "Leave it exposed just for testing," "I downloaded this skill that seemed useful": those were the phrases that resulted in 42.665 open ports and 341 poisoned recipes. Security isn't an advanced module to leave for later; it's the foundation, from the very first brick.
Self-check (optional): Which sentence sums up the family's safety lesson?
Key concepts
Exposed port + trust in someone else’s code.
Long-polling and running locally close off exposure.
Auditable tools in place of third-party skills.
Only your ID is served; everyone else is silently ignored.
🎯 Module summary
Next module:
2-3 — The world outside (AIOS, MemGPT, Operator) and the path forward