Carstairs vs OpenClaw:
Same Magic, None of the Risk
Why the agent that can't touch your computer is the one you actually want running your life.
In November 2025, an Austrian engineer shipped an open-source AI agent called OpenClaw. Within 48 hours it had over 100,000 GitHub stars. Within months it had something far less flattering: a security advisory from Cisco titled, more or less, "this is a nightmare."
Both of those things are worth paying attention to. Because OpenClaw got something profoundly right — and then demonstrated, in public, exactly why you don't want to run it.
What OpenClaw got right
OpenClaw proved a thesis a lot of people doubted: that millions of normal people want an AI agent that lives in their messaging apps and actually does things. Not a chatbot that explains how to do the thing — an agent that reads the email, checks the calendar, sends the reply, sets the reminder, and pings you when something needs attention.
That instinct is correct. Carstairs is built on the same one. The proactive agent that reaches out to you — that's the future, and OpenClaw deserves credit for making it undeniable.
What OpenClaw got terrifying
The way OpenClaw delivers that magic is by running on your own machine with broad access to your files, your inbox, your browser, and a shell. That's also how it became a security event:
- ClawJacked — researchers showed malicious websites could silently hijack a running OpenClaw instance by abusing trust assumptions around its local connection. (Reco)
- A poisoned plugin registry — roughly 12% of the skills in OpenClaw's add-on store were found to be malicious (341 of 2,857). (Barracuda)
- The industry's verdict — Cisco called personal agents like OpenClaw "a security nightmare," with parallel warnings from Microsoft, IBM, and Trend Micro. A whole cottage industry of "managed, safer OpenClaw" alternatives sprang up overnight. (Cisco)
- Viral adoption, invisible risk — Trend Micro made the same case in its teardown "Viral AI, Invisible Risks: What OpenClaw Reveals About Agentic Assistants" — the very features driving OpenClaw's explosive adoption, deep access and always-on autonomy, are exactly the ones quietly widening its attack surface. (Trend Micro)
Here's the thing to understand: none of this is a bug OpenClaw can patch away. Every one of those failures traces back to the same root — an agent that executes code on your machine with broad permissions. Give something that much reach, and "hijacked" stops being an if.
Why Carstairs is built the other way
Carstairs doesn't run on your computer. There's nothing to install, nothing to host, no permissions to grant, no plugin store to vet. He's a managed service that works the way a human assistant does — through email, chat, and your calendar.
He can't run a shell command, because there's no shell. He can't be hijacked through your browser, because he isn't in your browser. He can't leak your machine, because he never touches your machine.
The one thing Carstairs can't do is the one thing nobody safe should be doing in the first place.
This is the rare case where a constraint is the feature. By giving up "control of your computer," Carstairs gives up the entire category of risk that's currently making headlines — and loses nothing you'd actually want him to do.
And the part OpenClaw doesn't even attempt
Security is the reason to trust Carstairs. It isn't the reason to use him.
OpenClaw — and most of the AI-assistant field, honestly — is racing toward more actions. More integrations, more automations, more things it can click. Carstairs is built around something quieter and harder to copy: understanding.
He remembers what you decided and why. He knows that the person emailing you is the same one who promised something three weeks ago and went quiet. He notices the loop you left open and closes it before it becomes a problem. That's not automation — it's the difference between a macro and a chief of staff.
And unlike the tools that turn you into a workflow engineer, there's nothing to build. You forward an email. He takes it from there.
The honest comparison
| OpenClaw | Carstairs | |
|---|---|---|
| Lives | On your machine | Managed, server-side |
| Setup | A weekend (and a security audit) | Forward an email |
| Attack surface | Your whole digital life | None on your end |
| Superpower | Runs anything | Remembers everything |
| When it fails | Your inbox gets owned | An undo button |
The bottom line
OpenClaw showed everyone what they want: an agent that knows them and acts for them. It also showed everyone the bill that comes with letting that agent loose on their computer.
Carstairs is the version that pays attention instead of taking over. Same magic. None of the risk.
Forward your first email. See what he remembers by Friday.
Get Carstairs