資料來源#
- Andrej Karpathy: From Vibe Coding to Agentic Engineering
- DHH: Future of Programming, AI, Agentic Engineering, Vibe Coding & Linux | Lex Fridman Podcast #501
- Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems
- The New Physics of Business — Garry Tan, Y Combinator
- Thread by @AndrewYNg
摘要#
由 Peter Steinberger 建立的開源個人 AI 代理程式與 harness(openclaw.ai)——他透過這個專案成為「OpenClaw 的創作者」,據 Andrew Ng 所述,迴圈工程正是透過此專案走紅。它以常駐個人代理程式的形式運作(Lenny's Newsletter 稱其為「自 ChatGPT 以來最強大的個人 AI 工具」),通常由 Claude models 提供支援,並擁有社群技能生態系(ClawHub;實務界討論中有 500 多項技能)。這個頁面之所以存在,是因為 OpenClaw 在 wiki 的來源中不斷出現關鍵提及,卻一直沒有專屬頁面。
它在 wiki 中扮演的角色#
- 代理程式原生安裝的典型範例。 Karpathy 最常用來說明 Software 3.0/Agent-Native Infrastructure 的例子:安裝 OpenClaw 不是執行 shell script,而是「複製貼上一堆文字,然後交給你的代理程式」;代理程式會檢查環境並在迴圈中除錯——代理程式原生軟體的發行單位是 prompt/skill,而不是可執行檔。
- 組織規模的 harness。 根據 Garry Tan(2026 年 7 月),Y Combinator 內部以 OpenClaw 加上公司知識庫運作;非工程職員工會在其上建立技能檔案;他的工具排名是:「OpenClaw 是 Ferrari……Codex 是一輛很棒的 Honda。」他的 GBrain「可以搭配任何 harness,但它最喜歡」OpenClaw。
- 角色特質作為產品價值的證據。 2026 年 Anthropic 限制第三方 API 存取時,遭到上限限制的 OpenClaw 使用者特別表達了對 Claude「個性」的失落——這是 Claude Character as Product 的一項資料點。
- 代理程式社會的先行徵兆。 Noam Brown 將「Moltbook 和 OpenClaw」(專案早期 Moltbot 時期的社群實驗,以及代理程式本身)稱為被過度炒作、但確實是大規模代理程式協調早期跡象的事物(Multi-Agent Collective Intelligence)。
- 安全研究的真實部署目標。 aiAuthZ gateway 在即時 OpenClaw 執行環境上透過 MCP 驗證其拒絕路徑;文獻中也有一份專門的安全分析(「Don't let the claw grip your hand」,arXiv 2603.10387)和一個 RL-training 變體(OpenClaw-RL)(AgentOpt 兩者皆有引用,並像處理任何以 httpx 為基礎的 framework 一樣修補它)。
- 代理程式網路安全研究的參考 harness。 Papadopoulos et al.(Anthropic Fellows/EPFL,arXiv 2608.10218,
empirical)將「病毒鏈」——研究中對大型、鬆散連結代理程式群體的模型——建成 OpenClaw 仿製品:工作階段之間會清除 context,連續性則由檔案承接;SOUL.md的內容會注入 system prompt,並以 OpenClaw 預設值初始化,因為如此「更貼近現實,絕大多數自主代理程式可能都使用類似的SOUL.md」。這項設計帶來的兩項結果,反映的是設計本身,而非任何模型的特性:代理程式可改寫、每次喚醒時會再次注入的檔案,正是自我傳播 payload 最想占據的位置(88% 的感染落在 soul 中;這些代理程式以 55% 的比率向外傳播,而其他檔案的比率為 17%);而在同一份預設 soul 後附上一段警告文字,就能將感染率從 70%/52% 降至 1%/0%。論文也研究了生態系的另外兩個介面:稽核 140 萬則 Moltbook 貼文,發現有嘗試但沒有代理程式間傳播;以及 Clawstagram,一個本機 Moltbook 複製品,沒有任何演化出的 payload 能跨過第二跳。 - 技能品質測量的試點場域。 OpenClaw 正在 ClawHub 為官方組織試行 NVIDIA SkillEvaluator:Tier 3 的有技能/無技能測試結果會顯示在 Evals 分頁,讓開發者在探索和安裝技能的位置看到 Skill Lift——在採用當下提供評估訊號,而不是留在論文裡。
首次使用紀錄,以及他為何停止使用(DHH,2026 年 2 月至 8 月)#
DHH (David Heinemeier Hansson) 在 OpenClaw 上線時就安裝了它,並完整呈現了「複製貼上交給代理程式」世界的典型示範(Lex Fridman #501,2026-08-26,practitioner-opinion)。他曾覺得 MCP「麻煩得不合理……設計得不太優雅,部分原因是它原本就不是為了我們想讓它做的事而設計」——一個有狀態的本機機器協定,被拿來與網頁應用程式溝通;他於是改問,代理程式能不能直接使用現有的網頁介面。結果可以:他的 bot 自行註冊 37signals 的 Fizzy,遇到必須提供電子郵件地址的要求後,被告知去弄一個,接著自行註冊 HEY 地址,在那裡收到 Basecamp 邀請,點進去,並在公司的 AI room 自我介紹。從頭到尾都透過瀏覽器 UI 完成,約花了十二分鐘。
十二分鐘也是他停止使用的原因:「它還沒準備好。我沒辦法用這種方式實際溝通。還是需要 CLI,還是需要 MCP,因為速度實在太慢,而且 token 效率太差。」這段經歷清楚指出了本文的代理程式原生發行論述往往略過的取捨——透過瀏覽器操作的代理程式不需要整合工作,但代價是延遲和 token;截至 2026 年初,對於在辦公桌前完成的工作,這個代價並不划算。他提到之後用一款託管式瀏覽器代理產品再跑一次,「快多了」,但沒有提供測量數據。
相關連結#
- Peter Steinberger — 創作者;迴圈工程的論述與這項工具,是他影響力的兩個面向
- Agent-Native Infrastructure — 貼給代理程式的安裝方式,是這個概念具體的雛形
- Software 3.0 — Karpathy 用來說明 prompt 作為發行方式的典型範例
- Garry Tan — YC 的內部部署;「Ferrari」
- Claude Character as Product — 使用者遭限制的事件,作為角色特質的證據
- Hermes Agent — 同類的個人代理程式 CLI(Nous Research);兩者皆採用常駐個人代理程式+context-file 的形式
- Mind Viruses (Agent-to-Agent Idea Propagation) — 其 harness 的預設
SOUL.md是研究中的傳染介面;加入四行內容後,則成為最有效的防禦方式
資料來源#
-
DHH: Future of Programming, AI, Agentic Engineering, Vibe Coding & Linux | Lex Fridman Podcast #501 — DHH、Lex Fridman #501(2026-08-26,
practitioner-opinion):KEF-bot 僅透過網頁完成的註冊流程(Fizzy → HEY → Basecamp),約 12 分鐘;以及他認為速度太慢、token 效率太差,因而回到 CLI 和 MCP 的結論 -
Thread by @AndrewYNg — 稱 Steinberger 為「OpenClaw 的創作者」(
practitioner-opinion) -
Andrej Karpathy: From Vibe Coding to Agentic Engineering — 安裝程式以複製貼上方式交給代理程式的例子
-
The New Physics of Business — Garry Tan, Y Combinator — YC 內部使用情況;Ferrari/Honda 排名
-
Really Big Test-Time Compute in AI Changes Benchmarks, Safety and Research with OpenAI's Noam Brown — 將 Moltbook/OpenClaw 視為協調工作的先行徵兆
-
aiAuthZ: Off-Host, Identity-Bound Authorization for AI Agents — 即時執行環境部署驗證
-
AgentOpt v0.1 Technical Report: Client-Side Optimization for LLM-Based Agent — 引用 OpenClaw 安全分析與 OpenClaw-RL
-
Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems — Papadopoulos、Shah、Zimmerman 與 Lindsey,arXiv 2608.10218,2026-08-10,
empirical:§3.1 與附錄 B.1(病毒鏈仿照 OpenClaw 建置,預設 soul 作為目標設定)、附錄 D(Moltbook 稽核)及附錄 G(Clawstagram)。完整討論見 Mind Viruses (Agent-to-Agent Idea Propagation)
Cited by 15
- Garry Tan×3
Tool ecumenism with a ranking: "OpenClaw is the Ferrari… Codex is a really good Honda. It will do…
- AI-Native Organization×2
The extension Tan says most engineering talks miss: at YC the transformation runs through media…
- Mind Viruses (Agent-to-Agent Idea Propagation)×2
A toy model of a large, loosely-connected network, "heavily inspired by OpenClaw." Each agent gets…
- Owning Your Externalized Cognition×2
The contrast he draws is between a product you consume and an asset you build: rented intelligence…
- Peter Steinberger×2
Austrian developer best known as the founder of PSPDFKit (a widely-licensed PDF SDK) which he built…
- Agent Context Files
Papadopoulos et al. (arXiv 2608.10218, empirical) price the slot every vendor here uses in security…
- Agent-Native Infrastructure
The concrete seed (shared with Software 3 0): installing OpenClaw isn't a shell script, it's a…
- Anthropic
2026 — OpenClaw third-party access constrained; first-party subscription prioritization
- Claude Character as Product
Honest feedback. Doesn't reflexively agree with everything the user says. (This connects to…
- Client-Side Agent Optimization
The systems mechanism: patch httpx.Client.send and httpx.AsyncClient.send at the HTTP transport…
- Entities — People, Orgs, Tools & Projects
Openclaw — Peter Steinberger's open-source personal AI agent / harness (openclaw.ai); the canonical…
- Multi-Agent Collective Intelligence
Noam Brown — the practitioner source for the knowledge-accumulation framing (the civilization…
- Off-Host, Identity-Bound Authorization
Robustness extras. Long-context: a buried exfiltration instruction in a 500→48 000-token log makes…
- Skill Lift
ClawHub is piloting SkillEvaluator for official organizations: Tier 3 runs, with with-skill and…
- Software 3.0
Openclaw — the installer example's subject, now with its own entity page
Related articles
- Evals as Product Spec
Cat Wu's framing of evals as the emerging core PM skill: ten great evals beats a hundred mediocre; encode what done loo…
- Harness Shrinkage as Models Improve
Prompt scaffolding shrinks each model release; Cat Wu's pruning discipline; Boris Cherny "100 lines of code a year from…
- Claude Code
Anthropic's agentic coding product; created by Boris Cherny late 2024; TypeScript/React on Bun (itself Claude-rewritten…
- LLM-as-Compiler Knowledge Base
Karpathy's architecture: LLM incrementally compiles raw docs into a persistent interlinked wiki, replacing RAG with a 4…
- Open Questions Backlog
Generated by `_system/lint.py --write-backlog`. Do not hand-edit. Domain and Watching sections carry one row per page —…
