A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
An AI assistant that runs agents securely in their own containers. Lightweight, built to be easily understood and completely customized for your needs. nanoclaw.dev • OpenClaw is an impressive project, but I wouldn't have been able to sleep if I had given complex software I didn't understand full access to my life. OpenClaw has nearly half a million lines of code, 53 config files,…
⚠ The trust score below reflects the collection's repository only. The bundled units are not individually verified or scanned — review them before use.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
atomic_chat_list_modelsList all models available in the local Atomic Chat desktop app. Use this to see which models are loaded before calling atomic_chat_generate.List all models available in the local Atomic Chat desktop app. Use this to see which models are loaded before calling atomic_chat_generate.
No input schema was published for this tool.
atomic_chat_generateSend a prompt to a local Atomic Chat model and get a response. Good for cheaper/faster tasks like summarization, translation, or general queries. Use atomic_chat_list_models first to see available models.Send a prompt to a local Atomic Chat model and get a response. Good for cheaper/faster tasks like summarization, translation, or general queries. Use atomic_chat_list_models first to see available models.
No input schema was published for this tool.
ollama_list_modelsList all models installed in the local Ollama daemon. Use this to see which models are available before calling ollama_generate.List all models installed in the local Ollama daemon. Use this to see which models are available before calling ollama_generate.
No input schema was published for this tool.
ollama_generateSend a prompt to a local Ollama model and get a response. Good for cheaper/faster tasks like summarization, translation, or general queries. Use ollama_list_models first to see available models.Send a prompt to a local Ollama model and get a response. Good for cheaper/faster tasks like summarization, translation, or general queries. Use ollama_list_models first to see available models.
No input schema was published for this tool.
ollama_pull_modelPull (download) a model from the Ollama registry into the local daemon. Blocks until the download completes — large models can take several minutes.Pull (download) a model from the Ollama registry into the local daemon. Blocks until the download completes — large models can take several minutes.
No input schema was published for this tool.
ollama_delete_modelprivilegedDelete a locally installed model from the Ollama daemon to free disk space.Delete a locally installed model from the Ollama daemon to free disk space.
No input schema was published for this tool.
ollama_show_modelShow details for a locally installed model: modelfile, parameters, template, and architecture info.Show details for a locally installed model: modelfile, parameters, template, and architecture info.
No input schema was published for this tool.
ollama_list_runningList models currently loaded in memory, with memory usage and processor type (CPU/GPU). Use this to see what is warm and consuming resources.List models currently loaded in memory, with memory usage and processor type (CPU/GPU). Use this to see what is warm and consuming resources.
No input schema was published for this tool.
create_agentCreate a long-lived companion sub-agent (research assistant, task manager, specialist) — the name becomes your destination for it. May require admin approval before the agent is created. Fire-and-forget.Create a long-lived companion sub-agent (research assistant, task manager, specialist) — the name becomes your destination for it. May require admin approval before the agent is created. Fire-and-forget.
No input schema was published for this tool.
send_messageSend a message to a named destination.Send a message to a named destination.
No input schema was published for this tool.
send_fileSend a file to a named destination.Send a file to a named destination.
No input schema was published for this tool.
edit_messageprivilegedEdit a previously sent message. Targets the same destination the original message was sent to.Edit a previously sent message. Targets the same destination the original message was sent to.
No input schema was published for this tool.
add_reactionAdd an emoji reaction to a message.Add an emoji reaction to a message.
No input schema was published for this tool.
ask_user_questionAsk the user a multiple-choice question and wait for their response. This is a blocking call — execution pauses until the user responds or the timeout expires. Provide a short card title (e.g. "Confirm deletion") and an array of options — each option may be a plain string (used as both button label…Ask the user a multiple-choice question and wait for their response. This is a blocking call — execution pauses until the user responds or the timeout expires. Provide a short card title (e.g. "Confirm deletion") and an array of options — each option may be a plain string (used as both button label…
No input schema was published for this tool.
send_cardSend a structured card (interactive or display-only) to the current conversation.Send a structured card (interactive or display-only) to the current conversation.
No input schema was published for this tool.
install_packagesprivilegedInstall apt and/or npm packages into YOUR per-agent container image. Requires admin approval; fire-and-forget. On approval, the image is rebuilt and the container is restarted automatically.Install apt and/or npm packages into YOUR per-agent container image. Requires admin approval; fire-and-forget. On approval, the image is rebuilt and the container is restarted automatically.
No input schema was published for this tool.
add_mcp_serverWire an EXISTING third-party MCP server into YOUR per-agent runtime config. Provide either the local `command` + optional `args`/`env`, or its remote Streamable HTTP `url` (HTTPS; plain HTTP only for localhost / host.docker.internal). Requires admin approval; fire-and-forget.Wire an EXISTING third-party MCP server into YOUR per-agent runtime config. Provide either the local `command` + optional `args`/`env`, or its remote Streamable HTTP `url` (HTTPS; plain HTTP only for localhost / host.docker.internal). Requires admin approval; fire-and-forget.
No input schema was published for this tool.
17 of 17 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
An AI assistant that runs agents securely in their own containers. Lightweight, built to be easily understood and completely customized for your needs. nanoclaw.dev • OpenClaw is an impressive project, but I wouldn't have been able to sleep if I had given complex software I didn't understand full access to my life. OpenClaw has nearly half a million lines of code, 53 config files, and 70+ dependencies. Its security is at the application level (allowlists, pairing codes) rather than…
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.