# OpenClaw vs Hermes Agent: Two Open-Source Personal AI Agents Compared

> OpenClaw and Hermes Agent are MIT-licensed personal AI agents with shell, file and messaging access. A comparison of design, memory, skills and documented security issues.

FireAI Security & Research Team (HisnLabs) · Published 2026-09-30
Canonical: https://hisnlabs.com/en/blog/openclaw-vs-hermes-agent

OpenClaw and Hermes Agent are two open-source personal AI agents that run on a user’s own computer or server, take instructions through messaging apps and act with the permissions of the account that runs them. Both are published under the MIT licence. They differ in origin, in how they store what they learn and in how their security controls are arranged. This article compares them using the projects’ own documentation and published security reporting, and marks where the sources disagree or say nothing.

## Background

A personal agent is a language model connected to tools. The model does not only answer; it runs shell commands, reads and writes files, drives a browser and sends messages on the user’s behalf. The model’s instructions can come from the user, but also from any text the agent reads while working, such as a web page, an email or a chat message. That property, called prompt injection, is why the documentation of both projects gives security guidance and why the incidents below matter.

## What each project is

OpenClaw describes itself as an open-source AI assistant that runs on the user’s own computer and connects to more than twenty messaging platforms. Its README credits Peter Steinberger and the community, and states that the project is stewarded by the OpenClaw Foundation, described there as an independent 501(c)(3) nonprofit, with no paid tier or hosted service [[1]](https://github.com/openclaw/openclaw). The project was earlier called Clawdbot and then Moltbot; TechCrunch reported on 15 February 2026 that Steinberger was joining OpenAI and that, in the words of OpenAI’s chief executive, OpenClaw “will live in a foundation as an open source project that OpenAI will continue to support” [[3]](https://techcrunch.com/2026/02/15/openclaw-creator-peter-steinberger-joins-openai/).

Hermes Agent is built by Nous Research, whose repository calls it a self-improving agent with a built-in learning loop that creates skills from experience and builds a model of the user across sessions [[9]](https://github.com/NousResearch/hermes-agent). Its documentation lists Linux, macOS, WSL2, native Windows, NixOS and Android (Termux) as supported platforms [[10]](https://hermes-agent.nousresearch.com/docs/). The repository states the MIT licence. The sources fetched for this article do not give a reliable first-release date for Hermes Agent, so none is stated here.

## Architecture and reach on the computer

OpenClaw is organised around a Gateway, a local control plane that manages sessions, tools, events and channel connections, with a control interface, a command-line client and companion apps for voice, canvas, camera and device-local actions [[1]](https://github.com/openclaw/openclaw). Censys documented that the Gateway listens locally on TCP port 18789 by design, intended for local access or an SSH tunnel rather than direct exposure to the internet [[4]](https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant/). The OpenClaw documentation states that on a regular host install the Gateway binds to loopback, and that tools run on the host unless sandboxing is configured [[2]](https://docs.openclaw.ai/gateway/security).

Hermes Agent runs a single gateway process for messaging platforms and separates where commands execute from where the agent runs. Its repository lists seven terminal backends: local, Docker, SSH, Singularity, Modal, Daytona and Vercel Sandbox [[9]](https://github.com/NousResearch/hermes-agent). The documentation lists more than sixty built-in tools covering web search, extraction, browsing, vision and file operations, plus connections to Model Context Protocol servers [[10]](https://hermes-agent.nousresearch.com/docs/). With the local backend, commands run as the user; with a container or remote backend they run elsewhere.

## Extension, memory and models

OpenClaw is extended through tools, skills and plugins built with a plugin SDK and shared through ClawHub, its public registry [[1]](https://github.com/openclaw/openclaw). Hermes Agent uses skills that follow the open agentskills.io standard, which the agent can also write and refine itself after complex tasks [[9]](https://github.com/NousResearch/hermes-agent). The difference matters for supply chain risk: OpenClaw’s skills mostly come from a public registry, whereas Hermes Agent’s skills are partly generated by the agent from its own sessions.

On memory, OpenClaw states that user state, memory and credentials reside on the user’s hardware and not on OpenClaw servers [[1]](https://github.com/openclaw/openclaw). Hermes Agent keeps persistent memory and user profiles, and recalls past conversations through full-text (FTS5) session search combined with language-model summarisation [[9]](https://github.com/NousResearch/hermes-agent). Both projects are model-agnostic. OpenClaw works with hosted and local model providers as interchangeable plugins [[1]](https://github.com/openclaw/openclaw); Hermes Agent lists Nous Portal, OpenRouter, OpenAI and custom endpoints, switchable with a single command [[9]](https://github.com/NousResearch/hermes-agent). Which provider is used decides where prompts and file contents travel, and neither project can change that.

## Security model as documented

OpenClaw’s documentation defines one trusted boundary per Gateway and says it is not a security boundary between mutually adversarial users. Unknown senders on direct-message channels receive a pairing code by default, inbound messages are to be treated as untrusted input, and an `openclaw security audit` command reports configuration drift from the defaults [[2]](https://docs.openclaw.ai/gateway/security). The same page notes that agents with message-tool access can send across conversations and channel providers by default unless cross-provider messaging is restricted.

Hermes Agent’s security page describes eight layers. Dangerous commands go through an approval system with three modes (smart, manual and off) and a hard-coded blocklist for catastrophic commands. The Docker backend drops Linux capabilities and enforces `no-new-privileges`. Messaging access uses pairing codes with rate limits. File writes to credential stores such as `~/.ssh/` and `~/.aws/` are blocked, and a server-side request forgery guard rejects private, loopback and cloud-metadata addresses [[11]](https://hermes-agent.nousresearch.com/docs/user-guide/security). These are documented controls; the page does not report how often they are switched off in practice.

## Documented incidents and advisories

OpenClaw attracted most of the early security reporting. Censys counted growth from roughly 1,000 to 21,639 publicly reachable instances in under a week to 31 January 2026, noting that most required an authentication token [[4]](https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant/). Kaspersky reported nearly 1,000 installations reachable without authentication, caused partly by a default that trusts localhost connections when a reverse proxy forwards external requests, and described a researcher extracting private keys through instructions embedded in an email [[8]](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/).

Oasis Security disclosed “ClawJacked”: a malicious web page could open a WebSocket connection to the local Gateway, guess its password because localhost connections were not rate-limited, register as a trusted device and take control of the agent. The fix shipped in OpenClaw 2026.2.25, released on 26 February 2026 [[5]](https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html). Separately, Koi Security audited 2,857 skills on ClawHub and identified 341 malicious ones, 335 of them from one campaign it named ClawHavoc; eSecurity Planet reports that the skills were used to deliver the Atomic macOS Stealer, an infostealer [[6]](https://www.esecurityplanet.com/threats/hundreds-of-malicious-skills-found-in-openclaws-clawhub/). Paubox reports a different count, 386 malicious skills found by a researcher in early February 2026, all sharing one command-and-control address [[7]](https://www.paubox.com/blog/malicious-crypto-skills-compromise-openclaw-ai-assistant-users). The counts differ because the sources audited at different times and by different methods.

For Hermes Agent, the GitHub Advisory Database lists CVE-2026-9366, an injection issue in the function that scans project context files, rated moderate (CVSS 5.5), affecting versions before 0.15.0 and patched in 0.15.0; it was published on 26 May 2026 [[12]](https://github.com/advisories/GHSA-pgp4-xr4j-h5cg). Other advisories for the project appear in public vulnerability databases, but only this one was verified against its primary record for this article. The reporting reviewed contains no Hermes Agent counterpart to the malicious-skill campaign or the mass exposure documented for OpenClaw, which may reflect its later start or a smaller registry and is not evidence of absence.

| Aspect | OpenClaw | Hermes Agent |
| --- | --- | --- |
| Maker | Created by Peter Steinberger and community; OpenClaw Foundation (nonprofit) stewards it | Nous Research |
| Licence | MIT | MIT |
| Core design | Local Gateway with channels, tools and companion apps | Agent with learning loop and a single messaging gateway |
| Where commands run | On the host unless sandboxing is configured | Seven backends: local, Docker, SSH, Singularity, Modal, Daytona, Vercel Sandbox |
| Messaging | More than 20 platforms, including WhatsApp, Telegram, Slack, Discord, Signal, iMessage | Telegram, Discord, Slack, WhatsApp, Signal and others |
| Extension | Tools, skills and plugins; ClawHub registry | Skills (agentskills.io standard), self-written; MCP servers |
| Memory | State on the user’s hardware | Persistent memory, user profile, FTS5 session search |
| Models | Hosted and local providers | Nous Portal, OpenRouter, OpenAI, custom endpoints |
| Command approval | Tool policy and sandbox modes | Smart, manual or off, plus a hard-coded blocklist |
| Documented incidents | Exposed instances, ClawJacked, malicious ClawHub skills | CVE-2026-9366 (moderate); other advisories not verified here |

*Comparison compiled from the projects’ own documentation and the reporting cited above.*

> FireAI, the on-device firewall for macOS developed by HisnLabs, lists every connection an agent makes and lets you block one with a rule. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for Mac users

Neither project removes the underlying exposure: an agent that reads untrusted text and can run commands or send messages can be steered by that text. The practical differences are defaults and ecosystem. OpenClaw has the larger documented history of exposed Gateways and malicious registry skills, and its Gateway is a local network service that a browser can reach. Hermes Agent offers container and remote backends as first-class options and a command approval system, but the approval mode can be turned off, and self-written skills and persistent memory add their own persistence risks.

## Recommendations

1. Run either agent under a separate macOS user account or in a virtual machine or container, not in a personal account that holds keys and documents.
2. Keep the Gateway or API server on loopback and never forward its port; reach it through an SSH tunnel if remote access is needed.
3. Install skills only after reading their source, and treat instructions to run a shell command as a prerequisite as a warning sign.
4. Keep command approval on manual and update the agent when advisories are published.
5. Give the agent throwaway or narrowly scoped credentials for connected accounts.

## Relevance to FireAI

FireAI is a network firewall for macOS. It identifies each program by its code signature, so an agent appears as the interpreter that runs it, such as node or python3, and it has no integration with either project. It can ask before a new destination is contacted, block an app or a company with a [rule](https://hisnlabs.com/en/docs/per-app-rules), and stop new connections to everything outside the local network with the [kill switch](https://hisnlabs.com/en/docs/kill-switch). It does not read the contents of encrypted connections, and it does not restrict which files or commands an agent can use locally. A companion article describes the controls in detail.

## Limitations

- The comparison rests on project documentation and third-party reporting; no agent was tested for this article.
- Documented incidents reflect attention as much as risk: the more widely deployed and scrutinised project accumulates more reports.
- Counts of exposed instances and malicious skills differ between sources and change with time and method.
- Both projects release frequently, so version-specific statements may already be outdated.
- Hermes Agent’s first-release date and any advisories beyond CVE-2026-9366 were not verified from primary records.

## How FireAI and HisnLabs fit in

Agents run on your Mac. FireAI shows and controls where they connect.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download).

## Sources

- [OpenClaw: project repository and README (GitHub)](https://github.com/openclaw/openclaw)
- [OpenClaw documentation: Gateway security](https://docs.openclaw.ai/gateway/security)
- [TechCrunch: OpenClaw creator Peter Steinberger joins OpenAI (15 February 2026)](https://techcrunch.com/2026/02/15/openclaw-creator-peter-steinberger-joins-openai/)
- [Censys: OpenClaw in the Wild, mapping the public exposure of a viral AI assistant](https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant/)
- [The Hacker News: ClawJacked flaw lets malicious sites hijack local OpenClaw AI agents](https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html)
- [eSecurity Planet: Hundreds of malicious skills found in OpenClaw’s ClawHub](https://www.esecurityplanet.com/threats/hundreds-of-malicious-skills-found-in-openclaws-clawhub/)
- [Paubox: Malicious crypto skills compromise OpenClaw AI assistant users](https://www.paubox.com/blog/malicious-crypto-skills-compromise-openclaw-ai-assistant-users)
- [Kaspersky: New OpenClaw AI agent found unsafe for use](https://www.kaspersky.com/blog/openclaw-vulnerabilities-exposed/55263/)
- [Hermes Agent: project repository and README (GitHub, Nous Research)](https://github.com/NousResearch/hermes-agent)
- [Hermes Agent documentation (Nous Research)](https://hermes-agent.nousresearch.com/docs/)
- [Hermes Agent documentation: Security](https://hermes-agent.nousresearch.com/docs/user-guide/security)
- [GitHub Advisory Database: hermes-agent injection issue, CVE-2026-9366](https://github.com/advisories/GHSA-pgp4-xr4j-h5cg)
- [FireAI docs: Rules](https://hisnlabs.com/en/docs/per-app-rules)
- [FireAI docs: Kill switch](https://hisnlabs.com/en/docs/kill-switch)
