3 ms·
Does anyone know a Claw-like that: - doesnt do its own sandboxing (I'll set that up myself) - just has a web UI instead of wanting to use some weird proprieta
by bjackman 8mo ago
Does anyone know a Claw-like that:
- doesnt do its own sandboxing (I'll set that up myself)
- just has a web UI instead of wanting to use some weird proprietary messaging app as its interface?
- tokenless 8mo agoOpenclaw! You can sandbox anything yourself. Use a VM. It has a web ui.
- bjackman 8mo agoYeah I think this is gonna have to be the approach. But I don't like the fact that it has all the complexity of a baked in sandboxing solution and a big plugin architecture and blah blah blah. TBH maybe I should just vibe code my own...
- bspammer 8mo agoI don’t really understand the point of sandboxing if you’re going to give it access to all your accounts (which it needs to do anything useful). It reminds me of https://xkcd.com/1200/ https://xkcd.com/1200/
- bjackman 8mo agoYeah I have been planning to give it its own accounts on my self hosted services. I think the big challenge here is that I'd like my agent to be able to read my emails, but... Most of my accounts have Auth fallbacks via email :/ So really what I want is some sort of galaxy brained proxy where it can ask me for access to certain subsets of my inbox. No idea how to set that up though.
- tokenless 8mo ago> So really what I want is some sort of galaxy brained proxy where it can ask me for access to certain subsets of my inbox. No idea how to set that up though. Though of the same idea. You could run a proxy that IMAP downloads the emails and then filters and acts as IMAP server. SMTP could be done the same limited to certain email addresses. You could run an independent AI harmful detector just in case.
- bjackman 8mo agoYeah I think for SMTP it's easy since it's perfectly scalable to do manual approval for each mail. But not really sure how to set up safe search. One idea I had was to say "nobody would ever put a secret in the subject line, right..?". Then you could let the agent read all the headers and just have it ask permission to see the body. That's still not entirely safe since if you can search the body you can eventually infer the presence of arbitrary strings. But I think you could probably mitigate that risk by just setting up alerts for if the agent starts spamming loads of searches?
- tokenless 8mo agoBecause you don't give it access to all your accounts, you choose what. And files on your PC may be private and you don't want to risk exposing them. A use case may be for example give it access to your side project support email address, a test account on your site and web access.
- kzahel 8mo agohttps://yepanywhere.com/ https://yepanywhere.com/ But has no Cron system. Just relay / remote web UI that's mobile first. I might add Cron system to it, but I think special purpose tool is better / more focused (I am the author of this)
- bluesnowmonkey 8mo agoDepending on what you mean by claw-like, stumpy.ai is close. But it’s more security focused. Starts with “what can we let it do safely” instead of giving something shell access and then trying to lock it down after the fact.
- rane 8mo agoMoltis has a web chat UI at least. https://moltis.org/ https://moltis.org/