Carapace

puremachinery/carapace

Compare vs OpenClaw
healthy GitHub

A hardened Rust rewrite of OpenClaw that prioritizes security defaults and signed WASM plugins. It positions itself as the 'hard shell' alternative for users wary of the January 2026 OpenClaw disclosures.

Decision

Why choose Carapace over OpenClaw?

Quick recommendation layer first, deeper analysis second. Use this before diving into metrics and architecture details.

AI Decision Layer Measured Signals Below
Compare with OpenClaw
Why choose this
  • OS-level subprocess sandboxing and encrypted secret storage
  • Rust memory safety with low resource footprint
  • Signed WASM plugins with strict capability limits
Tradeoffs
  • Smaller community and fewer ready-made skills
  • Younger project (v0.8.0) with partial feature paths
  • Less cross-platform mobile support than OpenClaw
Best fit
  • Privacy-focused self-hosters
  • Security-conscious developers
  • Rust enthusiasts wanting local AI assistant
Avoid if
  • Users needing large plugin ecosystem
  • Non-technical users
  • Those wanting managed cloud service
Confidence & evidence
Good Confidence 70%
Freshly Reviewed
Full Rewrite

Repo README and commit history show active maintenance and detailed security model, but Reddit and Brave results are off-topic (gaming/biology) or OpenClaw-centric, leaving external sentiment unverified.

AI decision layer last reviewed Jul 13, 2026. Useful guidance with a reasonable evidence base behind it.

Last generated Jul 13, 2026
Last reviewed Jul 13, 2026
Refresh mode Full Rewrite

Source window: GitHub metadata, README, recent commits, latest release, Reddit, Brave search

Measured security
95
Measured memory
15 MB
GitHub Stars
47
Boot Time
30 ms
Memory
15 MB
Language
Rust

Community sentiment

10% Positive
21 Reddit Mentions
10 Web Results

Security radar

?

Scale: 10 = maximum safety, 1 = high risk

Star Growth (2026)

Last Scan: 7/20/2026, 1:44:13 PM
#rust #security #ai-assistant #openclaw-alternative #local-first

Carapace is a security-focused, open-source personal AI assistant written in Rust, explicitly built as a hardened alternative to OpenClaw/clawdbot. It runs locally on a user's machine and connects to multiple messaging channels (Matrix, Signal, Telegram, Discord, Slack, webhooks, console) while supporting a wide range of LLM providers including Anthropic, OpenAI, Ollama, Gemini, Bedrock, and local Claude CLI.

Its core architecture emphasizes secure defaults: localhost-only binding, OS credential store with AES-256-GCM fallback, OS-level subprocess sandboxing for protected paths, and a signed WASM plugin runtime with resource limits. The project documents a threat-by-threat comparison addressing the January 2026 OpenClaw security disclosures, covering unauthenticated access, plaintext secrets, supply chain risks, prompt injection, and SSRF.

Unlike OpenClaw's broad ecosystem and cross-platform reach, Carapace is younger (v0.8.0) and prioritizes stability on verified paths, with partial features explicitly flagged. It is best suited for technically inclined users who value a hard security shell over plug-and-play convenience.

Live Data Partner OpenClaw Seismograph
Threat Level elevated
Nomination

Add a new Claw

Publicly visible in our Open Registry.