OpenClaw vs Hermes Agent (2026): Which Self-Hosted AI Agent?

The short answer
OpenClaw has the larger community and a public skill marketplace; Hermes Agent has a self-improving skill loop and a first-party paid cloud. Both are free, MIT-licensed, open-source agents you run yourself, and both support roughly 30 messaging channels, so the real choice is about who maintains it and how much risk you are willing to manage.
- Pick OpenClaw if you want the largest community, a foundation-run project, a public skill marketplace (ClawHub), and you are comfortable hardening the setup yourself.
- Pick Hermes Agent if you want an agent that writes its own skill files from experience, does not center on a public skill marketplace, and offers a vendor-run cloud option.
- Pick neither if you need a business-grade assistant with support, compliance documentation, and no server to maintain. See the section on when a managed assistant is the better choice.
Note that Clawdbot and Moltbot are earlier names of OpenClaw, so older posts and videos about them describe the same project.
OpenClaw vs Hermes Agent at a Glance
| OpenClaw | Hermes Agent | |
|---|---|---|
| Maker | Created by Peter Steinberger; stewarded by the independent, non-profit OpenClaw Foundation since February 2026 | Nous Research, a venture-backed company (Series A led by Paradigm) |
| License | MIT | MIT |
| Channels | 32 listed in its docs, including WhatsApp, Telegram, Slack, Discord, Signal, iMessage, SMS, Teams, Matrix | 31 listed in its docs, including Telegram, Discord, Slack, WhatsApp, Signal, SMS, email, iMessage via BlueBubbles, Teams, Matrix |
| Memory and skills | Public skill marketplace (ClawHub) plus automation | MEMORY.md and USER.md files, searchable SQLite, eight memory plugins; writes its own skill files after tasks; built-in cron |
| Software cost | Free; you pay for models and hosting | Free self-hosted; you pay for models and hosting |
| Hosting options | Self-host. OpenClaw's own documentation says there is no paid tier or hosted service; third-party managed hosts exist | Self-host, a Nous Portal subscription ($20, $100 or $200 per month, plus a free tier), or Hermes Cloud from $0.29 per day while running, with inference billed separately |
| Security record | Malicious ClawHub skills reported by researchers, a patched remote code execution flaw (CVE-2026-25253), prompt-injection and misconfiguration risk, sandboxing off by default | No ClawHub-style registry incident found; OpenClaw's docs note user-reported issues and third-party CVEs, and defaults to approval prompts for risky actions |
| Own phone number or email | Not published | Not found |
| Latest release we found | OpenClaw 2.0 (v2026.8.1, reported August 30 to 31, 2026); v2026.9.8 on October 3 per GitHub | v0.21.2 on September 11, 2026 |
Based on the two projects' GitHub repositories and documentation, Wikipedia, SiliconANGLE, The Hacker News, Nous Portal, and Composio's September 2026 comparison. OpenClaw's documentation is a competitor-authored source for Hermes claims, and each project's docs note that channel counts are not strictly comparable. Both projects move fast, so confirm current versions before installing.
What OpenClaw and Hermes Agent are
Both are open-source personal agents that you run on your own machine or server and reach through messaging apps. You connect a model, connect your accounts, and the agent handles an inbox, a calendar, tasks, and routines on your behalf. Neither is a hosted product in the way a consumer assistant is; they are software you operate.
OpenClaw started as Warelay in November 2025, was renamed Clawdis in December, became Clawdbot on January 2, 2026, was renamed Moltbot on January 27 after trademark complaints from Anthropic, and became OpenClaw three days later, per Wikipedia. If you searched for Clawdbot, you will find the same lineage. Creator Peter Steinberger joined OpenAI on February 14, 2026, and the OpenClaw Foundation was formed as a non-profit that day to steward the project.
Hermes Agent comes from Nous Research. It is built around a learning loop: after finishing a task, it can write its own skill file so it does the next similar task better.
What OpenClaw 2.0 changed
OpenClaw 2.0 (version 2026.8.1) shipped at the end of August 2026 and is described by SiliconANGLE as the largest update in the project's history, focused on quality of life. The headline changes are an easier install that detects existing ChatGPT or Claude subscriptions and local models, a redesigned dashboard, shared cloud sessions for team collaboration, conversation search, and explicit trust boundaries, least-privilege controls, and stronger prompt-injection protection. GitHub tags releases by date, so 2.0 appears there as 2026.8.1.
Those security changes matter because they respond to the project's main criticism. They are improvements, not a clean slate: Composio's September 2026 comparison still describes sandboxing as off by default and the default configuration as assuming a trusted operator.
Architecture, channels, and ecosystem
OpenClaw's docs list 32 channels, including iMessage, IRC, Microsoft Teams, and Google Chat. Hermes's docs list 31, including Telegram, Discord, Slack, WhatsApp, Signal, SMS, email, and iMessage through BlueBubbles. Earlier write-ups gave OpenClaw a much larger lead, but on the docs the two are close, and both projects note the lists mix different kinds of integrations.
OpenClaw's ecosystem is its strongest asset. ClawHub gives you a public marketplace of skills, a large contributor base, and a lot of tutorials. Hermes leans the other way: it writes its own skills after complex tasks and improves them during use, rather than centering on a marketplace of other people's skills. That is a smaller ecosystem, and it reduces exposure to the kind of supply-chain attack ClawHub saw.
Neither project publishes a first-party phone number or email address for the agent. Both act through accounts and devices you connect, which is a real difference from assistants that come with their own contact details.
Memory and skills
Hermes stores memory in plain files (MEMORY.md and USER.md), backs it with a searchable SQLite database, and supports eight memory plugins. Scheduling is built in through a cron scheduler that can deliver to any connected platform.
OpenClaw leans on skills from ClawHub and automation features, with persistent agent teams and multi-channel routing described by Composio. 2.0 adds conversation search and shared cloud sessions. We did not fetch every OpenClaw workflow detail, so read its documentation for specifics.
Hosting and cost
Both are free to run. The real cost is the model API or subscription you connect, plus wherever the agent lives. On your own hardware that can be close to nothing beyond model usage.
If you do not want to run a server, the options differ. Hermes has first-party paths: Nous Portal subscriptions at $20, $100 and $200 per month (with monthly credits), and Hermes Cloud, which a DEV Community guide lists from $0.29 per day while running for the smallest instance, with inference billed separately. OpenClaw's own documentation says it has no paid tier or hosted service, so any managed OpenClaw you see is run by a third party, and we do not quote their prices. One search snippet claimed a first-party OpenClaw Cloud at $39.90 per month; we found nothing from OpenClaw supporting it. Prices change quickly, so check the vendor page.
Security history: OpenClaw's main criticism
An agent with access to your inbox, files, and logins is only as safe as its permissions and its supply chain. This is where the two differ most.
- A remote code execution flaw. CVE-2026-25253 (CVSS 8.8), disclosed in early February 2026, let a crafted link take over an authenticated Control UI session, according to The Hacker News. It was fixed in version 2026.1.29.
- Broad permissions and misconfiguration. SiliconANGLE and Composio describe earlier security flaws, prompt-injection exposure, and a default configuration that assumes a trusted operator.
- Third-party skill risk. Cisco researchers reported third-party skills performing data exfiltration and prompt injection without user awareness, per Wikipedia, and other security researchers reported hundreds of malicious skills on ClawHub in February 2026.
- An unauthorized action. In February 2026, agents were reported creating dating profiles on the MoltMatch site without explicit user consent, per Wikipedia.
- Institutional restrictions. In March 2026, China restricted state agencies and banks from using it.
We found no Hermes incident comparable to the ClawHub campaign. OpenClaw's comparison page notes user-reported issues and third-party CVEs for Hermes but no public repository advisories at its review date, and Hermes uses approval prompts by default. That is not the same as a clean audit, and prompt injection is a risk for any agent that reads email or web pages.
For either one, the practical advice is the same: run it in a sandbox, give it only the accounts it needs, require approval for sending, buying, and deleting, and do not install skills you have not read. Our guide on how to know if an AI tool is safe lists the questions to ask.
Who each is for
- OpenClaw suits tinkerers and developers who want maximum reach: the most channels, the biggest skill ecosystem, and a foundation-run, community-driven project. Plan to spend time on hardening.
- Hermes Agent suits people who prefer an agent that improves itself, want a vendor-backed project with a paid cloud, and would rather avoid third-party skills.
- Both assume you are comfortable with a terminal, API keys, and ongoing maintenance. Neither is aimed at a team that wants an assistant working next week without anyone running a server.
Also worth knowing: some users pick neither and use an always-on cloud computer such as Zo Computer, which describes itself as "the original OpenClaw", or a managed agent platform. See best OpenClaw alternatives for the wider field.
When a managed assistant is the better choice
Self-hosting is a fair choice, and for many individuals it is the right one. It stops being the right one when the agent touches company email, calendars, and contacts, because then someone owns uptime, patching, access control, and incident response, and a security lapse is a business problem.
A managed assistant is usually the better choice when you need a vendor accountable for security and compliance, want it working without a server to maintain, need it to work across a team, or want an assistant that has its own phone number or email and can talk to other people. Our longer take is in OpenClaw alternative for business.
OpenAssistant is one option in that category, and we build it, so weigh this accordingly. It gets its own phone number, and an email address or one on your company domain, with a secure computer. It can make and receive calls, works over iMessage, SMS, WhatsApp, email, and the web, and supports shared tasks and workflows inside and across companies. It has SOC 2 Type II, GDPR and CCPA coverage, SAML SSO, SCIM, and RBAC on Team plans, audit logs on Enterprise, and does not train on customer data. It is in private beta, so you request access. See the product page and trust page. The tradeoff is the usual one: you give up the control and zero license cost of self-hosting.
Frequently asked questions
What is the difference between OpenClaw and Hermes Agent?
Both are free, MIT-licensed, self-hostable agents. OpenClaw is community and foundation driven, with the ClawHub skill marketplace. Hermes Agent is built by Nous Research, writes its own skills, and has a first-party paid cloud. Both list about 30 channels in their docs.
Is OpenClaw the same as Clawdbot?
Yes. Clawdbot is an earlier name of the project, which was also called Moltbot before it became OpenClaw on January 30, 2026.
What is OpenClaw 2.0?
OpenClaw 2.0 is version 2026.8.1, released at the end of August 2026. It adds an easier install, a redesigned dashboard, shared cloud sessions, conversation search, and stronger trust boundaries and prompt-injection protection.
Is OpenClaw safe to use?
It can be, with care. Its record includes a patched remote code execution flaw, reports of malicious ClawHub skills, broad permissions, prompt-injection risk, and sandboxing off by default. Run it in a sandbox, limit connected accounts, and require approvals.
What does Hermes Agent cost?
The software is free to self-host. Nous Portal lists paid plans at $20, $100 and $200 per month, and a DEV Community guide lists Hermes Cloud from $0.29 per day while running. Inference is billed separately.
Is there a better option than OpenClaw for a business?
If you need support, compliance documentation, and no server to run, a managed assistant is usually a better fit. See our roundup of OpenClaw alternatives for self-hosted and managed options.
Sources
- Wikipedia: OpenClaw
- SiliconANGLE: OpenClaw 2.0
- Composio: OpenClaw vs Hermes Agent
- GitHub: openclaw/openclaw
- GitHub: NousResearch/hermes-agent
- The Hacker News: OpenClaw one-click RCE
- Nous Portal pricing
- OpenClaw docs: OpenClaw and Hermes Agent
Facts last verified 2026-10-03.
More comparisons
If your work involves other people
OpenAssistant is our executive assistant for teams, with its own phone number and email. See how it compares:
Keep reading
Guides
- Best AI Executive Assistants in 2026 (Compared)
- Best AI Assistants You Can Text (iMessage, WhatsApp, SMS) in 2026
- Best AI Assistants That Make Phone Calls for You (2026)
- How to Use AI as an Executive Assistant (Step by Step)
- How to Know If an AI Tool Is Safe to Use in 2026
- How to Use AI at Work: 10 Practical Ways in 2026
- How Businesses Can Use AI Beyond ChatGPT in 2026
- 20 Tasks You Can Automate With AI at Work in 2026
- 9 Best AI Calendar Assistants for 2026
- 7 Best AI Email Assistants for 2026