---
title: "Hermes vs OpenClaw: what a fresh install of each gives you"
description: "Hermes vs OpenClaw from a same-day install of both: default permissions, RAM, memory, Slack, the security record, and running costs at 10 and 25 people."
canonical: https://chickpea.co/blog/hermes-vs-openclaw
author: Pejman Pour-Moezzi (https://x.com/pejmanjohn)
published: 2026-09-30
verified: 2026-09-29
---

# Hermes vs OpenClaw: what a fresh install of each gives you

> Hermes vs OpenClaw from a same-day install of both: default permissions, RAM, memory, Slack, the security record, and running costs at 10 and 25 people.

By Pejman Pour-Moezzi, creator of Chickpea. Published September 30, 2026; facts checked September 29, 2026. The HTML page is at https://chickpea.co/blog/hermes-vs-openclaw; the site index for agents is at https://chickpea.co/llms.txt.

Install OpenClaw 2026.9.7 and its agent can run any command on the machine without asking. Install Hermes Agent v0.21.5 and `rm -rf` has to pass an approval check first. That gap in defaults is the biggest Hermes vs OpenClaw difference we found. Hermes, from Nous Research, keeps notes on you and writes its own skills. OpenClaw, from the OpenClaw Foundation, has phone apps, device nodes, and a documented team setup. Pick Hermes for memory and safer defaults, and OpenClaw for phone apps, devices, and a shared team gateway.

We installed both on September 29, 2026, from their official Docker images and install scripts, in throwaway containers. We connected no model and no accounts, so nothing here comes from a live conversation. Everything else comes from the two projects' docs, release notes, security advisories, users, and third-party researchers. We build Chickpea, which takes a different approach, and it appears in one section near the end.

## Key takeaways

- Pick Hermes Agent if you want an agent that prompts itself to write and refine skills from its work. It keeps 2,200 characters of notes and a 1,375-character profile of you. On a fresh install it holds a recursive delete or a download piped into a shell for approval.
- Pick OpenClaw if you want phone apps, devices, and a shared gateway: native iPhone and Android apps, device nodes for camera, screen, and voice, and a team setup with per-person sign-in and roles. Both reach 20+ chat channels.
- A fresh OpenClaw starts with full tool access, no approval prompts, and sandboxing off. A fresh Hermes starts with approvals on, but runs commands on whatever machine it sits on until you choose an isolated backend such as Docker. Both projects' security pages say everyone who can message a shared agent shares its authority.
- In our run, OpenClaw's official image was a 1.26 GB download and idled at 1.2 to 1.6 GiB of memory. Hermes's was 0.95 GB and idled at 0.2 to 0.4 GiB.
- Both are free, and on one shared gateway the model is most of the bill. At 25 people on medium use with a mid-tier model, one shared gateway runs about $142 a month on Hermes and $154 on OpenClaw, whose idle memory calls for a 4 GB server. One instance per person runs about $430 and $730. Two outside token tests found Hermes using 1.75 to 2.4 times OpenClaw's tokens, so its model bill may run higher than these figures.

## The short version

| | Hermes Agent | OpenClaw |
|---|---|---|
| Made by | Nous Research | OpenClaw Foundation, a non-profit |
| License | MIT | MIT |
| GitHub stars, September 29 | 250,133 | 390,817 |
| Release we installed | v0.21.5, September 24 | 2026.9.7, September 29 |
| Download and idle memory, our run | 0.95 GB image, 0.2 to 0.4 GiB | 1.26 GB image, 1.2 to 1.4 GiB, or 1.4 to 1.6 with Slack |
| Commands on a fresh install | Dangerous ones go through an approval check | Full access, no prompts |
| Sandbox by default | No. Runs on its host until you pick Docker, Modal, Daytona, or another backend | No. Off until you turn it on |
| Memory | Capped notes and a user profile, plus search over past sessions | Markdown memory files with search and promotion |
| Skills | 58 bundled, and it writes and refines its own | 51 bundled, 15 ready without setup, plus its ClawHub registry |
| Channels and apps | 20+ chat channels, plus desktop apps for Mac and Windows | 20+ chat channels, plus native apps for Mac, Windows, iPhone, and Android, and device nodes |
| Team option | Hermes Business, a hosted agent per member | The team setup, one shared gateway with sign-in and roles |
| Hosted by the maker | Hermes Cloud, from $0.56 a day | No |
| Published advisories | 10 in GitHub's database, 44 CVEs in NVD, [see the caveat](#the-security-record-with-dates) | 722 in its repository |

## What a fresh install lets the agent do

On OpenClaw, `openclaw exec-policy show` printed "full · no approval prompts · fallback deny", and `openclaw sandbox explain` showed the sandbox off. [Its exec approvals docs](https://docs.openclaw.ai/tools/exec-approvals) agree. Command security defaults to full on a gateway host, and approval prompts default to off. OpenClaw does have approvals, including automatic command review since 2026.9.4 and approve buttons in Slack. You turn them on with `openclaw exec-policy preset cautious`. Setting `agents.defaults.sandbox.mode` to `non-main` sandboxes every session except the agent's main one, and `all` sandboxes every session. `openclaw security audit`, run on the fresh install, found nothing critical and printed its trust model: "personal assistant (one trusted operator boundary), not hostile multi-tenant on one shared gateway."

On Hermes, a rule check flags risky commands such as `rm -rf`, and approvals default to a smart mode. A second model lets low-risk commands through, denies dangerous ones, and asks you about the rest. Scheduled and unattended runs deny anything that would need a prompt. The offline `hermes approvals test`, a dry run of the rule check, let `ls -la` through and held both `rm -rf` on a folder and `curl ... | bash` for approval, naming the rule each time. Since v0.21.0, writes to its instruction, skill, and memory files need approval too. Its dashboard refused to bind to a public address without an auth provider.

Hermes's weak spot is where commands run. The terminal backend defaults to `local`, so an approved `rm -rf` hits whatever machine Hermes sits on. [Hermes's security page](https://hermes-agent.nousresearch.com/docs/user-guide/security) recommends Docker, Modal, Daytona, or Vercel Sandbox for production gateways. To use Docker, set `terminal.backend` to `docker` in `config.yaml`. Its SECURITY.md says: "The only security boundary against an adversarial LLM is the operating system."

Hermes is the safer one to leave on defaults. Neither is a sandbox until you make it one.

## Installing and updating

OpenClaw installed in 51 seconds from a tagged release. Hermes took 150 seconds and pulled its main branch.

We ran both official install scripts on a clean Debian 12 container on an Apple silicon Mac. OpenClaw's script installed Node 24 and build tools, then the 2026.9.7 package from npm. Hermes's first attempt failed after about four minutes. The Node binary it bundles needs `libatomic.so.1`, a system library that a stripped-down Debian image does not ship. With it added, the script finished, cloning the main branch rather than a release tag. It brought its own Python 3.14, Node, ffmpeg, and ripgrep, then built a terminal UI and a web UI.

Hermes's folder came to 2.7 GB, runtimes included. OpenClaw's npm package was 731 MB, not counting the Node and build tools it installed system-wide. The official Docker images are the other way around on size. OpenClaw's is 1.26 GB compressed for arm64, and Hermes's is 0.95 GB.

OpenClaw's non-interactive onboarding will not start without `--accept-risk`, a flag whose help text reads "Acknowledge that agents are powerful and full system access is risky." It stores model credentials as plain text unless you choose secret references.

Both ship often. Since July 1, OpenClaw has published 17 stable releases and 14 prereleases, and it keeps an "extended-stable" line it calls its LTS equivalent. Hermes has published 18. Update breakage is the OpenClaw complaint we saw most often, in four of the 24 user comments we collected. "Every single time I update OpenClaw to latest version, something breaks," an r/openclaw user wrote on September 8. On Hacker News in August, another said OpenClaw "broke every update for a month, so I gave up and moved to Hermes." r/openclaw also carries accusations that pro-Hermes comments are astroturfed, so read the Reddit quotes here as anecdotes. Hermes updates break things too. The author of Hermes issue #16744 wrote that a Slack setup "stopped working after I ran" `hermes update`. OpenClaw 2026.9.7 now backs up every state database before a migration and restores it on rollback.

## OpenClaw vs Hermes on memory and skills

Memory and self-written skills are Hermes's headline features. OpenClaw has memory and, since 2026.9.4, a way to build skills, but you start the skill-building yourself.

Hermes keeps two capped files, 2,200 characters of notes and a 1,375-character profile of you. It prompts itself to save to memory every 10 turns of conversation and to consider writing a skill every 15 tool-calling iterations. A background curator reviews the skills it wrote, merges overlaps, and archives stale ones. It never deletes on its own. An r/openclaw user who switched in April said Hermes was "completing tasks that I had to configure openclaw to do over weeks due to poor memory." One critic describes the same feature from the other side, in a post titled "I tried Hermes so you don't have to." They wrote, "It's self improving. It will overwrite your edits."

OpenClaw keeps Markdown memory files with search, and a `promote` command that ranks recent recalls and can append the top ones to MEMORY.md. Since 2026.9.4 you can ask it to turn past conversations into skills in a chat you steer. It ships 51 bundled skills, 15 of them ready without extra setup, and installs more from ClawHub, its public registry.

Hermes's fixed prompt is large. Its offline `hermes prompt-size` command reported a 16.3 KB system prompt, or 12.8 KB when it simulates Slack. Tool definitions for its 24 default tools add 42.6 KB. That is roughly 14,000 to 15,000 tokens before your first message. OpenClaw has no offline equivalent, so we could not measure it without a model. Two tests we found show OpenClaw using fewer tokens. An r/hermesagent user ran both for a full day, counted 42 million tokens on OpenClaw against 73.5 million on Hermes, and still concluded "Hermes won." GMI Cloud's May 7 test of one prompt found OpenClaw at 15,000 tokens on each of two runs, and Hermes at 36,000 and then 30,000. Those tests put Hermes at 1.75 to 2.4 times OpenClaw's tokens.

## Channels and Slack

Both reach 20+ chat channels, including iMessage, and both have desktop apps. OpenClaw adds native iPhone and Android apps and device nodes for camera, screen, and voice. Hermes adds email and Home Assistant as channels.

In Slack, the two differ mostly in setup and rendering, from our installs and each project's docs:

| | Hermes Agent | OpenClaw |
|---|---|---|
| How Slack is added | Built in. `hermes slack manifest` writes the Slack app manifest | A plugin, `@openclaw/slack`, installed in 20 seconds in our run without a restart |
| Bot scopes requested | 17 in the manifest we generated | 23 in the documented base manifest |
| Connection | Socket Mode | Socket Mode, HTTP, or a relay |
| Who can talk to it | Nobody until you list Slack member IDs | Allowlisted channels, with a mention required, and a pairing code for DMs |
| Replies | Block Kit, with streaming and task cards as settings you turn on | Streamed task cards by default, native tables up to 100 rows, native charts |
| Approvals in Slack | One-tap buttons for dangerous commands | Buttons for command and plugin approvals |

Since 2026.9.7, other bots in the workspace can also trigger OpenClaw when `allowBots` is unset, still under its mention and access rules. Its loop protection pauses a pair of bots for a minute after 20 exchanges in 60 seconds.

Hermes's generated manifest includes a `/yolo` slash command, the Slack version of the `--yolo` flag that bypasses dangerous-command approvals. Hermes keeps each person's conversation separate in a shared channel, though everyone still shares one memory and profile. Decide who can reach the bot before you install it in a busy workspace.

## The security record, with dates

OpenClaw's record is longer, and its latest batch covered bugs already fixed. Hermes's is shorter, but two advisories list no fix and a 13-finding audit is still open.

OpenClaw has published 722 security advisories since January 31: 14 critical, 249 high, 390 medium, and 69 low. Most landed in February and March, and none in July or August. Then the foundation published 75 on September 11, each for a bug already fixed in a release between 2026.7.1 and 2026.9.3. Two touch Slack. A bug rated 8.8 let group DMs skip sender allowlists until 2026.8.1, and one rated 6.5 let Slack file downloads skip a conversation check.

The early incidents came in January and February. CVE-2026-25253, rated 8.8, let a crafted link steal the gateway token, and OpenClaw fixed it in 2026.1.29. Koi Security found 341 malicious skills among 2,857 on ClawHub and named the campaign ClawHavoc, and Antiy CERT counted 1,184 malicious packages in ClawHub's history as of February 5. Censys counted 21,639 exposed instances on January 31. We covered [what that record means for a team](/blog/openclaw-alternative-for-teams) in September.

Hermes has no advisories in its own repository. GitHub's database lists 10, one of them high and two with no fix listed. NVD lists 44 CVEs, mostly filed by VulDB, and has marked all of them deferred rather than analyzed. CVE-2026-71963, rated 8.8, was published September 3. It let a malicious repository's git config run code in versions 0.18.2 to 0.21.0. An independent audit filed in April as issue #7826 reported "4 Critical, 9 High severity findings in default configuration" and is still open. In June, a user found Hermes's web search calls going to Parallel.ai "even though I never configured any backend or API key." Nous reverted the routing.

Do not rank them by count. OpenClaw's foundation files advisories in bulk. Hermes's SECURITY.md says heuristic bypasses "don't receive advisories," and outside filers wrote most of its CVEs. The counts measure how each project discloses as much as how many bugs it has.

## What each costs to run

The software is free. The bill depends on whether a team shares one gateway or runs one instance each. The token tests we found suggest Hermes's model bill runs higher than the table shows.

The table assumes medium use, 20 requests a person a week, on a mid-tier model at about $0.06 a request, paid to the provider at list price. [Our comparison pages](/compare/hermes) use the same cost assumptions.

| Setup | 10 people | 25 people |
|---|---:|---:|
| One shared Hermes gateway on a $12 server | $64 | $142 |
| One shared OpenClaw gateway on a $24, 4 GB server | $76 | $154 |
| One Hermes instance per person, a $12 server each | $172 | $430 |
| One OpenClaw instance per person, a $24 server each | $292 | $730 |
| Hermes Cloud, one Medium instance per person | $222 | $556 |
| One instance per person, on laptops you already own | $52 | $130 |

A frontier model makes the model bill $130 a month at 10 people and $325 a month at 25. OpenClaw's docs give 1 GB of memory as the minimum and 2 GB as the recommendation. With the Slack plugin loaded it sat at 1.4 to 1.6 GiB idle in our run, so we priced it on a 4 GB server at about $24. Hermes idled under 0.4 GiB and fits the $12 server.

Nous sells model credit as a subscription, from $20 a month for $22 of credit. Hermes Cloud hosts the agent for $0.56 a day on a Medium instance with 2 GB and 4 vCPUs, plus inference. The OpenClaw Foundation does not host OpenClaw, though third parties such as Hostinger do.

## Sharing one agent with a team

OpenClaw says to run one gateway for each group of people who trust each other, and Hermes calls itself single-tenant.

OpenClaw's [team setup](https://docs.openclaw.ai/start/teams) puts a whole team on one gateway. People sign in to the Control UI through Tailscale or an identity-aware proxy such as Cloudflare Access. Sessions record who started, owns, and steered them, and teammates can add their own model accounts. Named operator roles limit which sessions, agents, and scopes each person gets, and can require that their sessions run sandboxed. The same page says: "Everyone who can message a tool-enabled agent shares that agent's delegated tool authority." For people who should not share that, it says to run one gateway per tenant, and its docs mark the tool for that, Fleet, as experimental.

Hermes's SECURITY.md calls it "a single-tenant personal agent" and says "within the authorized set, all callers are equally trusted." Nous's team product, Hermes Business, gives every member their own hosted agent on Nous infrastructure, one shared balance with per-member spending caps, and a team skill library. Issue #527 asks for role-based access on messaging platforms and #34352 for multi-tenant isolation. Both are open.

One r/openclaw user whose team gave each person their own Hermes or OpenClaw explained why in May. "A single shared Hermes instance means shared profiles, shared memory, shared skill drift," they wrote, adding that OpenClaw workspaces are "not a hard sandbox, just a default cwd." One team made a shared Hermes work. "Our nontechnical teammates can ask and answer their own data questions via Slack," a Hacker News commenter wrote of Hermes in June. OpenAI's [Dots agents](/blog/openai-dots) go the other way, taking instructions only from their owner in Slack.

## Where Hermes is the better choice

- You want it to remember you. It keeps capped notes and a profile of you, prompts itself to save every 10 turns, and searches past sessions.
- You want it to write and refine its own skills, with a curator that archives the stale ones.
- You want approvals on by default. Risky commands go through an approval check, unattended runs deny what would need a prompt, and the dashboard will not go public without auth.
- You want a small server. It idled under 0.4 GiB in our run and fits a $12 one.
- You want the maker to host it. Hermes Cloud hosts one for you, and Hermes Business gives each teammate one plus shared skills.
- You are leaving OpenClaw. `hermes claw migrate --dry-run` read our fresh OpenClaw state and checked 29 categories, including persona, memory, skills, and channel settings. It imports secrets only if you ask.

## Where OpenClaw is the better choice

- You want native iPhone and Android apps and device nodes for camera, screen, and voice, which Hermes does not have.
- You want one shared gateway for people who trust each other, with per-person sign-in, operator roles, and shared sessions that record who did what. The open source Hermes has no equivalent.
- You want native Slack tables and charts.
- You want a project run by a non-profit foundation, with an extended-stable release line it calls its LTS equivalent.

## How to choose

For your own agent, pick Hermes if you care most about memory and approvals on by default, and OpenClaw if you care most about phone apps and devices. For a team whose members trust each other and want one agent, OpenClaw's team setup is the documented path. For a team where each person should have their own, it is Hermes Business or one instance each. Neither starts sandboxed, so do this before you connect real accounts. On Hermes, set `terminal.backend` to `docker`. On OpenClaw, run `openclaw exec-policy preset cautious` and set `agents.defaults.sandbox.mode` to `all`, or to `non-main` if your own main session should stay on the host.

## If you want a shared agent for a team in Slack

OpenClaw's team setup gives a trusting team one shared gateway on a server someone runs, where everyone who can message it shares its authority. Hermes Business gives each person their own agent. We build a third option, shared agents you mention by Slack handle.

In [Chickpea](/), each Agent is a Slack handle with its own instructions, model, memory, skills, and connected accounts, and nothing carries over between Agents. Credentials never enter the model's context. Chickpea attaches the secret to the outbound request, inside an allowlist of that connector's hosts. Sending, deleting, publishing, and bulk changes [wait for a person](https://docs.chickpea.co/security/authority-and-confirmation/) unless the Agent's saved instructions allow that class of action. A check outside the model refuses any connector write the current Slack message did not ask for. Owners, Admins, and Members manage Agents by asking in Slack, each within their role. A change that widens an Agent's reach comes back as a proposal to approve in the thread. It deploys to your own Cloudflare account on the Free plan, or to a Node host, and runs on Workers AI or your own model keys.

It is narrower than both. It works in Slack only, has no device or desktop of its own, and one deployment serves one workspace. Its Agents do not write their own skills, so you write them or import them from GitHub. On the Cloudflare Free plan, Chickpea adds nothing to the model bill, $52 a month at 10 people and $130 at 25 under the assumptions above. Agent handles need a paid Slack plan, and the optional coding sandbox needs Workers Paid. [The pricing page](/pricing) shows the math. The detail is in [Chickpea vs Hermes Agent](/compare/hermes) and [Chickpea vs OpenClaw](/compare/openclaw).

## FAQ

### Is Hermes better than OpenClaw?

For a personal agent that keeps memory and writes skills, yes. For native phone apps and one gateway a whole team can share, OpenClaw is. One r/openclaw commenter runs both and uses each to fix the other when an update breaks it.

### Is Hermes more secure than OpenClaw?

Its defaults are safer. It puts dangerous commands through an approval check, and OpenClaw does not until you configure it. Neither sandboxes commands by default, both treat one gateway as one trust boundary, and their advisory counts are not comparable because the two projects disclose differently.

### What about NanoClaw and ZeroClaw?

They are smaller projects in the same space, and we did not test them. [NanoClaw](https://github.com/nanocoai/nanoclaw) is MIT licensed, has about 31,000 stars, and describes itself as a lighter OpenClaw alternative that runs in containers on Anthropic's Agents SDK. [ZeroClaw](https://github.com/zeroclaw-labs/zeroclaw) is Apache 2.0, has about 33,000 stars, and is a small personal-assistant runtime written in Rust.

### Which uses fewer tokens, Hermes or OpenClaw?

OpenClaw, in the two token tests we found. Hermes's fixed prompt measured about 55 to 59 KB offline in our run, roughly 14,000 to 15,000 tokens, and one full-day side-by-side test counted 42 million tokens on OpenClaw against 73.5 million on Hermes. We did not run a live model, so we have no per-task figure of our own.

### Can I move from OpenClaw to Hermes?

Yes. `hermes claw migrate` imports your persona, memories, skills, command allowlist, and channel settings from `~/.openclaw`, and API keys only with `--migrate-secrets`. Stop the gateway with `hermes gateway stop`, then run it with `--dry-run`. It refuses while the gateway is up, because Slack, Telegram, and Discord allow one active session per bot token.

### Are Hermes and OpenClaw free?

Yes. Both are MIT licensed. On a shared gateway or laptops, the model is the real bill, about $52 a month at 10 people and $130 at 25 on medium use with a mid-tier model, before any server. Hermes's may run higher, per the token tests above. Nous also sells model credit from $20 a month and hosting from $0.56 a day, and the OpenClaw Foundation offers no hosted version.

## Sources

OpenClaw: [repository and README](https://github.com/openclaw/openclaw), [team setup](https://docs.openclaw.ai/start/teams), [exec approvals](https://docs.openclaw.ai/tools/exec-approvals), [exec-policy presets](https://docs.openclaw.ai/cli/approvals), [sandboxing](https://docs.openclaw.ai/gateway/sandboxing), [security](https://docs.openclaw.ai/gateway/security), [multi-tenant hosting](https://docs.openclaw.ai/gateway/multi-tenant-hosting), [Slack manifest and scopes](https://docs.openclaw.ai/channels/slack/manifest-and-scopes), [Slack message behavior](https://docs.openclaw.ai/channels/slack/messaging), [Slack tables, charts, and approvals](https://docs.openclaw.ai/channels/slack/rich-messages), [bot loop protection](https://docs.openclaw.ai/channels/bot-loop-protection), [hosting FAQ](https://docs.openclaw.ai/help/faq-first-run/providers-and-hosting), [changelog](https://github.com/openclaw/openclaw/tree/main/CHANGELOG), [SECURITY.md](https://github.com/openclaw/openclaw/blob/main/SECURITY.md) (all checked September 29, 2026).
Hermes Agent: [repository and README](https://github.com/NousResearch/hermes-agent), [security](https://hermes-agent.nousresearch.com/docs/user-guide/security), [Slack](https://hermes-agent.nousresearch.com/docs/user-guide/messaging/slack), [messaging platforms](https://hermes-agent.nousresearch.com/docs/user-guide/messaging), [releases](https://github.com/NousResearch/hermes-agent/releases), [SECURITY.md](https://github.com/NousResearch/hermes-agent/blob/main/SECURITY.md), [Hermes Cloud and Nous Portal plans](https://portal.nousresearch.com/cloud), [Hermes Business](https://portal.nousresearch.com/business) (all checked September 29, 2026).
Security records: [OpenClaw security advisories](https://github.com/openclaw/openclaw/security/advisories), [GitHub advisories for hermes-agent](https://github.com/advisories?query=hermes-agent), [CVE-2026-25253](https://nvd.nist.gov/vuln/detail/CVE-2026-25253), [CVE-2026-71963](https://nvd.nist.gov/vuln/detail/CVE-2026-71963), [Hermes issue #7826](https://github.com/NousResearch/hermes-agent/issues/7826), [Hermes issue #45058](https://github.com/NousResearch/hermes-agent/issues/45058) (all checked September 29, 2026). [The Hacker News on Koi Security's ClawHub findings](https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html) (February 2026), [Antiy CERT's ClawHavoc analysis](https://www.antiy.net/p/clawhavoc-analysis-of-large-scale-poisoning-campaign-targeting-the-openclaw-skill-market-for-ai-agents/) (February 6, 2026), [Censys on exposed OpenClaw instances](https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant/) (January 31, 2026).
Tests: our own installs of both official Docker images and install scripts, September 29, 2026, with no model key, so no live conversations. [GMI Cloud's token test](https://www.gmicloud.ai/en/blog/hermes-vs-openclaw-ai-agent-comparison-2026) (May 7, 2026).
Users: [r/openclaw, "OpenClaw vs Hermes Agent, my experience after testing both"](https://www.reddit.com/r/openclaw/comments/1sky2w1/openclaw_vs_hermes_agent_my_experience_after/) (April 14, 2026, with replies into September), [r/openclaw, switching for memory](https://www.reddit.com/r/openclaw/comments/1swc620/openclaw_vs_hermes/) (April 26), [r/openclaw, "I tried Hermes so you don't have to"](https://www.reddit.com/r/openclaw/comments/1se64gt/i_tried_hermes_so_you_dont_have_to/) (April 6), [r/openclaw, one agent each for a team](https://www.reddit.com/r/openclaw/comments/1t852tn/) (May 9), [r/openclaw, updates](https://www.reddit.com/r/openclaw/comments/1waqwug/everytime_i_update_openclaw_it_makes_me_wanna_try/) (September 8), [r/hermesagent, a full-day side-by-side test](https://www.reddit.com/r/hermesagent/comments/1ujucjo/hermes_vs_openclaw_a_full_day_sidebyside_test/) (June 30), [r/hermesagent, unannounced search routing](https://www.reddit.com/r/hermesagent/comments/1u5ukz6/) (June 14). Hacker News: [thenbrent](https://news.ycombinator.com/item?id=49282146) (August 13), [brettcvz](https://news.ycombinator.com/item?id=48587502) (June 18). GitHub: [Hermes issue #16744](https://github.com/NousResearch/hermes-agent/issues/16744), [#527](https://github.com/NousResearch/hermes-agent/issues/527), [#34352](https://github.com/NousResearch/hermes-agent/issues/34352) (checked September 29, 2026).
Other projects: [NanoClaw](https://github.com/nanocoai/nanoclaw), [ZeroClaw](https://github.com/zeroclaw-labs/zeroclaw) (checked September 29, 2026).
Chickpea: [security model](https://docs.chickpea.co/security/security-model/), [authority and confirmation](https://docs.chickpea.co/security/authority-and-confirmation/), [skills](https://docs.chickpea.co/agents/skills/), [get started on Cloudflare](https://docs.chickpea.co/start/get-started-cloudflare/) (verified September 4 to 18, 2026), [pricing](/pricing), [Chickpea vs Hermes Agent](/compare/hermes) and [Chickpea vs OpenClaw](/compare/openclaw) (updated September 29, 2026).

Facts checked September 29, 2026. Both projects ship several releases a month, and the defaults, advisory counts, and star counts here are the most likely to move. We re-check the register behind this page at 30, 60, and 90 days.
