
Hermes vs OpenClaw comes down to what you want the agent to be. Hermes Agent, from Nous Research, is a self-improving agent that writes its own skills and keeps memory, with a terminal UI and a messaging gateway. OpenClaw is a personal assistant built around one gateway that connects to about 30 chat channels and a public skill registry. Both are MIT-licensed, both officially support Linux, and both need the same care: keep them off the open internet and snapshot before every update.
Who this is for: you want to self-host one AI agent in a home lab or on a VPS, and you want to know which one to set up first.
How this comparison works: it compares both agents from each project's official docs and repo as of 9 October 2026. Lab measurements will follow on the VM spec below. Until then, you see a placeholder where a measured number belongs. I do not print numbers I have not measured.
Hermes vs OpenClaw at a glance
Every product fact below is as of October 2026. Both projects ship often, so verify each one in the Hermes Agent docs and the OpenClaw docs before you rely on it.
| Factor | Hermes Agent | OpenClaw |
|---|---|---|
| Maker | Nous Research | OpenClaw Foundation (created by Peter Steinberger) |
| License | MIT | MIT |
| Latest stable (8 Oct 2026) | v0.21.6 | 2026.9.9 |
| Core idea | Agent that learns: memory, self-written skills, scheduled tasks | Personal assistant across chat apps, with a skill registry (ClawHub) |
| Native install | Official install script with pinned Python and Node.js | Official install script or npm; Node.js 24.16+ or 26.1+ |
| Docker image | nousresearch/hermes-agent | ghcr.io/openclaw/openclaw |
| Docker setup | docker run or a short compose file | Repo checkout plus setup.sh and Docker Compose |
| Main ports | 8642 (API, off by default), 9119 (dashboard) | 18789 (dashboard and WebSocket) |
| Default bind, native install | 127.0.0.1 | Loopback |
| Default bind, in Docker | Dashboard on 0.0.0.0 | Gateway on the LAN |
| Run as a service | hermes gateway install (systemd) | openclaw gateway install (systemd) |
| Update | hermes update --backup; new image in Docker | openclaw update; new image tag in Docker |
| Built-in backup | hermes backup / hermes import | openclaw backup create --verify |
| Local models | Yes (llama.cpp or Ollama); needs 64,000+ tokens of context | Yes (managed llama.cpp, Ollama, LM Studio and more) |
| Published GitHub advisories (9 Oct 2026) | None listed | 722, each with a patched version listed |
The advisory count needs context. OpenClaw grew very fast in early 2026 and drew heavy security research. A long advisory list shows scrutiny and fixes, not only risk. An empty list does not prove that Hermes has fewer flaws. It may have had less scrutiny so far.
The planned test VM
Both agents will get the same VM spec, matching the install guides on this site.
| Setting | Value |
|---|---|
| OS | Ubuntu Server 24.04 LTS |
| vCPUs / RAM / disk | 2 / 4 GB / 32 GB |
| Network | NAT, no inbound ports |
| Hermes install | Official script, systemd user service |
| OpenClaw install | Docker Compose, pinned pre-built image, gateway port bound to localhost |
| Model | The same cloud model for both |
The full steps are in two companion guides: install Hermes Agent on an Ubuntu VM and install OpenClaw in an Ubuntu VM with Docker Compose.
Install and setup
Hermes installs with one script. It brings its own pinned Python and Node.js, so it does not clash with what is on the VM. Setup is a few commands: hermes model, hermes tools and, for chat apps, hermes gateway setup. As of October 2026, pip and Homebrew installs are not supported.
OpenClaw also has a one-line installer that installs Node.js if needed and starts onboarding. Its Docker route has more parts. You clone the repo, run setup.sh, and manage a Compose stack with a gateway service and a CLI service. The compose file publishes three ports on all interfaces by default, so you should edit it before first start.
For a first-time self-hoster, Hermes asks for fewer decisions up front. OpenClaw's Docker route gives more control but needs more care.
Security defaults
Both projects are honest about risk. Neither one claims to contain a misbehaving model on its own.
- Hermes says the operating system is the only real security boundary. By default, its local terminal backend runs commands on the host with no isolation. Dangerous commands need approval, and the gateway denies every chat user who is not on an allowlist or paired.
- OpenClaw says sandboxing is off by default and is "not a perfect security boundary" when on. It ships a
security auditcommand and a documented hardened baseline. Its docs state that container images default to an exposed bind, which they pair with required token auth.
The skill supply chain needs care on both. OpenClaw has ClawHub, a public registry of community skills. In early 2026, researchers found hundreds of malicious skills there. OpenClaw responded with VirusTotal scanning, but its own announcement says a clean scan does not mean a skill is safe. Hermes also writes skills from your use, but its Skills Hub can install community skills from registries, ClawHub included, after a security scan. On either agent, read a third-party skill before you install it.
For both, the VM is what turns "the agent ran a bad command" into "I reverted a snapshot". The post on disadvantages of server virtualization covers the limits of VM isolation too.
Ports and remote access
Neither agent needs an inbound port for chat apps. Telegram, Discord and the rest work over outbound connections. You only need a port to reach the web dashboard.
For both, the safe pattern is the same. Keep the dashboard on the VM's localhost and open an SSH tunnel from your own computer. Hermes uses port 9119 for its dashboard. OpenClaw uses port 18789. Never forward either port on your router. On 31 January 2026, Censys counted 21,639 OpenClaw instances exposed on the internet, and most still asked for a token. "Most" is not good enough.
Updates and recovery
This is where a VM pays for itself.
| Task | Hermes Agent | OpenClaw |
|---|---|---|
| Update | hermes update --backup | openclaw update --dry-run, then openclaw update |
| Pin a version | Docker image tag | openclaw update --tag or a Docker image tag |
| Where state lives | ~/.hermes/ | ~/.openclaw plus an auth-profile secrets folder |
| Rollback warning | Do not delete the data folder to repair an install | Downgrading does not reverse config or database changes |
| Best rollback | VM snapshot | VM snapshot |
Both store state in SQLite, and both backups contain credentials. Encrypt them. With Hermes, do not put the data folder on a hypervisor shared folder, because the docs warn that some cross-VM mounts can corrupt the database.
Which one fits your setup?
Choose Hermes Agent if
- You want an agent that runs tasks, remembers context and improves its own skills over time.
- You prefer a single install script and a simple systemd service.
- You want an agent that writes most of its own skills, and you will install third-party skills only after you read them.
Choose OpenClaw if
- You want one assistant across many chat apps, including WhatsApp, Signal and Microsoft Teams. (iMessage needs a Mac, so it does not fit a Linux-only VM.)
- You want ready-made community skills and accept the duty to read them first.
- You are comfortable with Docker Compose and a few security settings.
Can you run both?
Yes, but give each its own VM. OpenClaw's docs say to keep one trust boundary per gateway. Two small VMs also mean two separate snapshot histories, so a bad update to one never touches the other. A home lab makes this cheap. See what a home lab is for ways to start with hardware you already own.
Home VM or VPS?
Both agents run on a small VPS. The OpenClaw docs include guides for several VPS providers, and the Hermes README mentions a $5 VPS. A VPS runs around the clock without a spare PC. A home VM costs nothing extra and keeps your data at home. The rules do not change: an SSH-only firewall, no public dashboard port, and snapshots or backups before updates. If you want an always-on box at home, the home server setup guide covers the hardware.
FAQ
Is Hermes better than OpenClaw?
Neither is better for everyone. Hermes suits people who want a learning agent with a simple install. OpenClaw suits people who want one assistant across many chat apps. Try both in separate VMs for a week and keep the one you use.
Are Hermes Agent and OpenClaw free?
Both are open source under the MIT license. You pay for the model you connect, unless you run a local model. A VPS, if you use one, has its own cost.
Can Hermes and OpenClaw use local models?
Yes. Both can use llama.cpp or Ollama. Hermes rejects models with less than 64,000 tokens of context, so raise Ollama's default. Local models need much more RAM than the agents themselves.
Which is safer to self-host?
Neither is safe by default on the open internet. Both can install community skills, so read each one first. OpenClaw has more published fixes and a security audit command. In both cases, a VM, localhost-only ports and snapshots do most of the work.
Do I need Docker for either one?
No. Both have native installers and official Docker images. Docker gives you pinned versions and easy rebuilds. A VM gives you stronger isolation and snapshots. The guide to containers vs virtual machines explains the trade-off.
No comments:
Post a Comment