Claw-Empire Agent Office
Run multiple AI coding agents as a local, visual software company.
The evidence shows loopback-only local modes, a non-root Docker user, read-only CI permissions, isolated git worktrees, merge-on-CEO-approval, and a control for killing stuck tasks, which adequately support least privilege, confirmation, and management of external effects for ordinary use. The README identifies SQLite storage, external model and messenger connections, API/OAuth credentials, AES-256-GCM encryption for messenger tokens, and explicit 200/401/503 inbox authentication outcomes. Deductions apply because automated installation executes scripts, initializes submodules, and may modify AGENTS.md, while agents can run commands, contact providers, and send messages without a complete per-action authorization model or exhaustive data-flow inventory. Encryption can fall back to SESSION_SECRET, with no shown rotation or key-separation procedure. Dependencies use a fixed pnpm release, frozen lockfile installation, and minimal CI permissions, but no dependency audit results, SBOM, signing, or vulnerability mitigation record is shown. Worktrees provide a limited recovery boundary, yet systematic rollback is not documented for installation, migrations, messages, database changes, or autonomous actions. The Apache license and copyright contact establish basic attribution, but no third-party attribution inventory is supplied. No direct red-line evidence is present.
README, package.json, and CI are broadly consistent about version 2.0.4, Node 22, builds, type checking, OpenAPI checks, and test commands; server tests also use isolated SQLite and log paths. However, SECURITY.md says only the 1.2.x line is supported while the advertised current release is 2.0.4, preventing full self-consistency credit. Runtime prerequisites and dependencies are described and the pnpm version is pinned, but the product depends on numerous third-party CLIs, APIs, OAuth systems, messenger services, and browser components without complete fallback behavior for unavailable or incompatible components. Health checks, inbox status codes, a 409 conflict case, logs, and validation commands provide useful failure signals, but the supplied evidence does not comprehensively document errors and recovery for agent execution, merging, or provider failures.
Six office/workflow packs, four UI languages, cross-platform installation, Docker, local and Tailscale modes, and CLI/OAuth/API plus messenger integrations thoroughly address varied audiences and scenarios. Capability categories and setup paths are clear, and ordinary messages are distinguished from CEO directives beginning with $. Deductions apply because permission boundaries, allowable command scope, unsupported cases, and constraints around autonomous collaboration, skill uploads, project-path routing, and cross-provider behavior are not comprehensively specified. The evidence also does not fully define ambiguity handling, confirmation, or refusal once a $ directive enters complex delegation. Environment fit is strongly supported by macOS, Linux, Windows, Docker, Node 22 prerequisites, and explicit loopback configurations.
The README has clear navigation, feature and technology tables, staged installation, verification commands, examples, release-note links, API and security-document entry points, and multilingual editions, earning strong information-architecture and installation scores. Version 2.0.4 agrees between README and package.json and has a named release-note path. Deductions apply because the package is still named climpire while the product is Claw-Empire, and the security support table remains on 1.2.x. Examples cover installation, health checks, inbox behavior, Docker, messaging, and sample outputs, but there is no visible centralized FAQ or comprehensive troubleshooting guide. Limitations are only indirectly mentioned through prerequisites and configuration notes rather than a dedicated limitations, risks, or unsupported-features section. The full Apache-2.0 license, copyright owner, email contact, private vulnerability channel, and response targets are clear; routine maintenance ownership, current stable-line responsibility, and general support routes remain incomplete, and publisher identity is unknown.
The product exposes concrete, usable outputs through an office view, kanban board, reports, meeting minutes, PowerPoint export, messenger entry points, agent controls, and isolated workspaces. Unifying several CLI, OAuth, and API agents behind a local interface, with workflow packs, live state, and approval-based merging, offers clear marginal value over a single-agent workflow. Cost-benefit is only adequately addressed because the evidence does not quantify setup and maintenance effort, model/API spending, resource usage, latency, or realized gains from multi-agent collaboration; the 600-plus skills and broad integration surface also create configuration and security overhead.
Many central claims map to concrete README features, package scripts and dependencies, CI stages, isolated test setup, the security policy, and the license. Version, Node requirements, and test commands receive useful cross-file corroboration. Deductions apply because the supplied test bodies contain only an environment-baseline smoke test and frontend test initialization, which cannot statically substantiate the extensive end-to-end, security, and scale claims; CI configuration shows intended checks, not that this revision passed them. Marketing phrases such as “all data stays on your machine,” “secure” OAuth, “real autonomous collaboration,” and “production-oriented” are mixed with factual descriptions without consistently stating assumptions, exceptions, or inference, so fact/inference separation is weak.
- SECURITY.md lists only 1.2.x as supported while the current product is advertised as 2.0.4; confirm the actual 2.x security-maintenance and patch policy before deployment.
- The one-click path executes repository scripts, initializes submodules, and may modify AGENTS.md in the repository or OpenClaw workspace; inspect the scripts and write targets and install in an isolated environment.
- Local-first does not mean no data leaves the machine: prompts, project context, and messages may be sent to configured CLI, OAuth, external LLM API, or messenger providers.
- Agents can execute commands, manipulate worktrees, send messages, and invoke external services; constrain credentials, filesystem scope, network egress, and merge authority before using production repositories or sensitive data.
- Token encryption can fall back to SESSION_SECRET; use a separate high-entropy OAUTH_ENCRYPTION_SECRET and establish backup, rotation, and recovery procedures.
- The supplied test evidence is thin and does not establish the README's broad functionality, security, or reliability claims; no code or tests were executed for this assessment.
What does this agent do, and when should you use it?
Claw-Empire is a local-first AI agent office simulator that organizes Claude Code, Codex CLI, Gemini CLI, OpenCode, Kimi Code, and other providers as a virtual company. Its React, Vite, Tailwind CSS, and PixiJS frontend supplies the pixel-art office, Kanban board, chat, and settings experience, while Express, SQLite, and WebSocket handle APIs, persistence, and live state. A user acts as CEO, delegates work across departments, convenes meetings, and reviews tasks performed in isolated Git worktrees before approval and merge. The system produces task deliverables, consolidated reports, meeting minutes, and PowerPoint presentations through six workflow packs spanning development, reporting, web research, fiction, video pre-production, and roleplay. It runs locally by default and also includes a production-oriented Docker deployment, although external execution still depends on the configured CLI, OAuth, or API provider.
Requests enter through CEO Chat, the Kanban board, direct messenger sessions, or POST /api/inbox; messages beginning with “$” become CEO directives and can carry project_path, project_context, and skipPlannedMeeting. The orchestrator can hold a team-leader meeting, route work to Planning and named departments, and broadcast task and agent state over WebSocket. Agents execute through local CLI processes, GitHub or Google OAuth, or direct endpoints configured under Settings > API, including OpenAI, Anthropic, Google, Ollama, OpenRouter, Together, Groq, Cerebras, and custom providers. Work can be isolated in per-agent Git branches and worktrees, with merging deferred until CEO approval. The UI manages Inbox, Planned, Collaborating, In Progress, Review, and Done states, along with hiring, manual assignment, skills, XP rankings, meetings, and termination of stuck processes. Outputs include task artifacts, detailed and consolidated reports, meeting minutes, PowerPoint decks, and machine-readable communication-test evidence. Telegram, WhatsApp, Discord, Google Chat, Slack, Signal, and iMessage sessions can run directly from the application or optionally through OpenClaw.
- An engineering lead using Claude Code, Codex CLI, and Gemini CLI who wants one board for delegation, live progress, and approval of agent-produced changes.
- A software team running parallel tasks that needs each agent isolated in a Git worktree until a human approves the merge.
- A privacy-conscious individual or organization that wants company state stored in local SQLite and the control plane bound to localhost by default.
- A research or editorial team using the report or web_research_report packs for source collection, fact checking, review, reports, and slide generation.
- A creative team coordinating worldbuilding, scripts, shot lists, dialogue, and quality checks through the novel, video_preprod, or roleplay packs.
- A manager who wants to issue “$” directives from Telegram, Slack, Discord, or another documented messenger and receive execution updates.
What are this agent's strengths and limitations?
- One interface covers CLI, OAuth, and direct API execution, with explicit support for Claude Code, Codex CLI, Gemini CLI, OpenCode, Kimi Code, and additional providers.
- Per-agent Git worktree isolation and CEO-controlled merging provide a concrete safety boundary for parallel software changes.
- The product goes beyond chat with a visual office, full Kanban lifecycle, meetings, multi-round review, active-process control, report archives, and PowerPoint output.
- Local SQLite persistence, AES-256-GCM token encryption, and a default 127.0.0.1 bind support local-first operation.
- It supplies macOS, Linux, and Windows setup scripts, a non-root Docker path, and documented frontend, API, and Playwright E2E checks.
- Local setup requires Node.js 22+, pnpm, Git, and repository submodules; CLI mode additionally requires separate installation and authentication for each coding tool.
- The orchestration layer is local, but cloud-backed CLIs, OAuth flows, and APIs still need network access, accounts, credentials, and potentially paid usage.
- Skills learn/unlearn automation is currently designed for CLI-capable providers, so direct API users may not receive equivalent behavior.
- Secure operation adds configuration work: encryption secrets must be managed, remote API/WebSocket access should use API_AUTH_TOKEN, and /api/inbox needs a separate shared secret.
- Automatic updates are off by default and can be blocked by a dirty worktree, a non-fast-forward branch, or active work; diverged branches require operator recovery.
How do you install or deploy this agent?
Prerequisites are Node.js 22 or newer, pnpm, Git, and at least one supported CLI, OAuth account, or direct API provider. On macOS or Linux run:
git clone https://github.com/GreenSheep01201/claw-empire.git
cd claw-empire
git submodule update --init --recursive
bash install.sh
pnpm dev:localOn Windows PowerShell run:
git clone https://github.com/GreenSheep01201/claw-empire.git
cd claw-empire
git submodule update --init --recursive
powershell -ExecutionPolicy Bypass -File .\install.ps1
pnpm dev:localOpen http://127.0.0.1:8800 and verify the backend with curl -s http://127.0.0.1:8790/healthz. For manual setup, copy .env.example to .env and set OAUTH_ENCRYPTION_SECRET; INBOX_WEBHOOK_SECRET is additionally required for /api/inbox. For containers, copy .env.example to .env.docker, place sensitive variables in the local .env.docker.private file, and run docker compose up -d --build; the documented container URL is http://127.0.0.1:8790.
How do you use this agent?
After startup, configure an installed Claude Code, Codex CLI, Gemini CLI, OpenCode, or Kimi Code executable and model under Settings > CLI Tools. Alternatively, add a direct key under Settings > API or connect a supported GitHub or Google OAuth flow. Create a request in chat or on the board, then select the relevant agents, departments, workflow pack, and project path. Ordinary messages become direct conversations; a message prefixed with “$” enters the CEO directive flow, which asks whether to hold a leaders’ meeting and which project_path or project_context to use. A first API invocation can be tested after setting INBOX_WEBHOOK_SECRET:
curl -X POST http://127.0.0.1:8790/api/inbox -H "content-type: application/json" -H "x-inbox-secret: $INBOX_WEBHOOK_SECRET" -d '{"source":"telegram","author":"ceo","text":"$Hotfix production login bug immediately","skipPlannedMeeting":true,"project_context":"existing project"}'A matching secret should return 200; a missing or mismatched header returns 401, while an unconfigured server secret returns 503. Follow execution through the Kanban stages and inspect the final result through task reports, meeting minutes, report history, or PowerPoint export.
How does this agent compare with similar options?
Compared with routing messenger traffic through OpenClaw, Claw-Empire can operate documented Telegram, WhatsApp, Discord, Google Chat, Slack, Signal, and iMessage sessions directly; only webhook/inbox flows and the optional OpenClaw bridge require /api/inbox and INBOX_WEBHOOK_SECRET. For model execution, the CLI path supports the documented skills learn/unlearn automation, while direct APIs avoid local CLI installation but have feature tradeoffs.