# nanocoai/nanoclaw

A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK

- **Type:** Collection
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Author:** nanocoai
- **License:** MIT
- **Source:** https://github.com/nanocoai/nanoclaw

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 39 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-08-28T18:37:49.066Z
- **Version scanned:** HEAD
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

17 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `atomic_chat_list_models` — List all models available in the local Atomic Chat desktop app. Use this to see which models are loaded before calling atomic_chat_generate.
- `atomic_chat_generate` — Send a prompt to a local Atomic Chat model and get a response. Good for cheaper/faster tasks like summarization, translation, or general queries. Use atomic_cha
- `ollama_list_models` — List all models installed in the local Ollama daemon. Use this to see which models are available before calling ollama_generate.
- `ollama_generate` — Send a prompt to a local Ollama model and get a response. Good for cheaper/faster tasks like summarization, translation, or general queries. Use ollama_list_mod
- `ollama_pull_model` — Pull (download) a model from the Ollama registry into the local daemon. Blocks until the download completes — large models can take several minutes.
- `ollama_delete_model` — Delete a locally installed model from the Ollama daemon to free disk space.
- `ollama_show_model` — Show details for a locally installed model: modelfile, parameters, template, and architecture info.
- `ollama_list_running` — List models currently loaded in memory, with memory usage and processor type (CPU/GPU). Use this to see what is warm and consuming resources.
- `create_agent` — Create a long-lived companion sub-agent (research assistant, task manager, specialist) — the name becomes your destination for it. May require admin approval be
- `send_message` — Send a message to a named destination.
- `send_file` — Send a file to a named destination.
- `edit_message` — Edit a previously sent message. Targets the same destination the original message was sent to.
- `add_reaction` — Add an emoji reaction to a message.
- `ask_user_question` — Ask the user a multiple-choice question and wait for their response. This is a blocking call — execution pauses until the user responds or the timeout expires. 
- `send_card` — Send a structured card (interactive or display-only) to the current conversation.
- `install_packages` — Install apt and/or npm packages into YOUR per-agent container image. Requires admin approval; fire-and-forget. On approval, the image is rebuilt and the contain
- `add_mcp_server` — Wire an EXISTING third-party MCP server into YOUR per-agent runtime config. Provide either the local `command` + optional `args`/`env`, or its remote Streamable

## Install

This is a collection — a bundle whose contents each install separately and are not individually verified. Resolve the unit you want and plan that install instead.

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; installs 55 bundled units.
- Floor 42, ceiling 78 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/nanocoai%2Fnanoclaw
- Install plan: https://forgeregistry.com/api/v1/packages/nanocoai%2Fnanoclaw/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/nanocoai%2Fnanoclaw
- HTML page: https://forgeregistry.com/registry/nanocoai%2Fnanoclaw
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
