SkillAgentSearch skills...

openfang

Open-source Agent Operating System

Install / Use

claude mcp add RightNow-AI -- npx -y github:RightNow-AI/openfang

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

91/100

Supported Platforms

Claude Code
Claude Desktop
<p align="center"> <img src="public/assets/openfang-logo.png" width="160" alt="OpenFang Logo" /> </p> <h1 align="center">OpenFang</h1> <h3 align="center">The Agent Operating System</h3> <p align="center"> Open-source Agent OS built in Rust. 137K LOC. 14 crates. 1,767+ tests. Zero clippy warnings.<br/> <strong>One binary. Battle-tested. Agents that actually work for you.</strong> </p> <p align="center"> <a href="https://openfang.sh/docs">Documentation</a> &bull; <a href="https://openfang.sh/docs/getting-started">Quick Start</a> &bull; <a href="https://x.com/openfangg">Twitter / X</a> </p> <p align="center"> <img src="https://img.shields.io/badge/language-Rust-orange?style=flat-square" alt="Rust" /> <img src="https://img.shields.io/badge/license-MIT-blue?style=flat-square" alt="MIT" /> <img src="https://img.shields.io/badge/version-0.6.9-green?style=flat-square" alt="v0.6.9" /> <img src="https://img.shields.io/badge/tests-2,696%2B%20passing-brightgreen?style=flat-square" alt="Tests" /> <img src="https://img.shields.io/badge/clippy-0%20warnings-brightgreen?style=flat-square" alt="Clippy" /> <a href="https://www.buymeacoffee.com/openfang" target="_blank"><img src="https://img.shields.io/badge/Buy%20Me%20a%20Coffee-FFDD00?style=flat-square&logo=buy-me-a-coffee&logoColor=black" alt="Buy Me A Coffee" /></a> </p>

v0.5.10 (April 2026)

OpenFang is feature complete but still pre-1.0. Expect rough edges and breaking changes between minor versions. We ship fast and fix fast. Pin to a specific commit for production use until v1.0. Report issues here.


What is OpenFang?

OpenFang is an open-source Agent Operating System. Not a chatbot framework. Not a Python wrapper around an LLM. Not a "multi-agent orchestrator." A full operating system for autonomous agents, built from scratch in Rust.

Traditional agent frameworks wait for you to type something. OpenFang runs autonomous agents that work for you: on schedules, 24/7, building knowledge graphs, monitoring targets, generating leads, managing your social media, and reporting results to your dashboard.

The entire system compiles to a single ~32MB binary. One install, one command, your agents are live.

curl -fsSL https://openfang.sh/install | sh
openfang init
openfang start
# Dashboard live at http://localhost:4200
<details> <summary><strong>Windows</strong></summary>
irm https://openfang.sh/install.ps1 | iex
openfang init
openfang start
</details>

Hands: Agents That Actually Do Things

<p align="center"><em>"Traditional agents wait for you to type. Hands work <strong>for</strong> you."</em></p>

Hands are OpenFang's core innovation. Pre-built autonomous capability packages that run independently, on schedules, without you having to prompt them. This is not a chatbot. This is an agent that wakes up at 6 AM, researches your competitors, builds a knowledge graph, scores the findings, and delivers a report to your Telegram before you've had coffee.

Each Hand bundles:

  • HAND.toml: manifest declaring tools, settings, requirements, and dashboard metrics.
  • System Prompt: multi-phase operational playbook. Not a one-liner. These are 500+ word expert procedures.
  • SKILL.md: domain expertise reference injected into context at runtime.
  • Guardrails: approval gates for sensitive actions (e.g. Browser Hand requires approval before any purchase).

All compiled into the binary. No downloading, no pip install, no Docker pull.

The 7 Bundled Hands

| Hand | What It Actually Does | |------|----------------------| | Clip | Takes a YouTube URL, downloads it, identifies the best moments, cuts them into vertical shorts with captions and thumbnails, optionally adds AI voice-over, and publishes to Telegram and WhatsApp. 8-phase pipeline. FFmpeg + yt-dlp + 5 STT backends. | | Lead | Runs daily. Discovers prospects matching your ICP, enriches them with web research, scores 0-100, deduplicates against your existing database, and delivers qualified leads in CSV/JSON/Markdown. Builds ICP profiles over time. | | Collector | OSINT grade intelligence. You give it a target (company, person, topic). It monitors continuously: change detection, sentiment tracking, knowledge graph construction, and critical alerts when something important shifts. | | Predictor | Superforecasting engine. Collects signals from multiple sources, builds calibrated reasoning chains, makes predictions with confidence intervals, and tracks its own accuracy using Brier scores. Has a contrarian mode that deliberately argues against consensus. | | Researcher | Deep autonomous researcher. Cross-references multiple sources, evaluates credibility using CRAAP criteria (Currency, Relevance, Authority, Accuracy, Purpose), generates cited reports with APA formatting, supports multiple languages. | | Twitter | Autonomous Twitter/X account manager. Creates content in 7 rotating formats, schedules posts for optimal engagement, responds to mentions, tracks performance metrics. Has an approval queue, so nothing posts without your OK. | | Browser | Web automation agent. Navigates sites, fills forms, clicks buttons, handles multi-step workflows. Uses Playwright bridge with session persistence. Mandatory purchase approval gate: it will never spend your money without explicit confirmation. |

# Activate the Researcher Hand. It starts working immediately.
openfang hand activate researcher

# Check its progress anytime
openfang hand status researcher

# Activate lead generation on a daily schedule
openfang hand activate lead

# Pause without losing state
openfang hand pause lead

# See all available Hands
openfang hand list

Build your own. Define a HAND.toml with tools, settings, and a system prompt. Publish to FangHub.


OpenFang vs The Landscape

<p align="center"> <img src="public/assets/openfang-vs-claws.png" width="600" alt="OpenFang vs OpenClaw vs ZeroClaw" /> </p>

Benchmarks: Measured, Not Marketed

All data from official documentation and public repositories, February 2026.

Cold Start Time (lower is better)

ZeroClaw   ██░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░   10 ms
OpenFang   ██████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░  180 ms    ★
LangGraph  █████████████████░░░░░░░░░░░░░░░░░░░░░░░░░  2.5 sec
CrewAI     ████████████████████░░░░░░░░░░░░░░░░░░░░░░  3.0 sec
AutoGen    ██████████████████████████░░░░░░░░░░░░░░░░░  4.0 sec
OpenClaw   █████████████████████████████████████████░░  5.98 sec

Idle Memory Usage (lower is better)

ZeroClaw   █░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░    5 MB
OpenFang   ████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░   40 MB    ★
LangGraph  ██████████████████░░░░░░░░░░░░░░░░░░░░░░░░░  180 MB
CrewAI     ████████████████████░░░░░░░░░░░░░░░░░░░░░░░  200 MB
AutoGen    █████████████████████████░░░░░░░░░░░░░░░░░░  250 MB
OpenClaw   ████████████████████████████████████████░░░░  394 MB

Install Size (lower is better)

ZeroClaw   █░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░  8.8 MB
OpenFang   ███░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░   32 MB    ★
CrewAI     ████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░  100 MB
LangGraph  ████████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░  150 MB
AutoGen    ████████████████░░░░░░░░░░░░░░░░░░░░░░░░░░░  200 MB
OpenClaw   ████████████████████████████████████████░░░░  500 MB

Security Systems (higher is better)

OpenFang   ████████████████████████████████████████████   16      ★
ZeroClaw   ███████████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░    6
OpenClaw   ████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░    3
AutoGen    █████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░    2
LangGraph  █████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░    2
CrewAI     ███░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░    1

Channel Adapters (higher is better)

OpenFang   ████████████████████████████████████████████   40      ★
ZeroClaw   ███████████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░   15
OpenClaw   █████████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░   13
CrewAI     ░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░    0
AutoGen    ░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░    0
LangGraph  ░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░    0

LLM Providers (higher is better)

ZeroClaw   ████████████████████████████████████████████   28
OpenFang   ██████████████████████████████████████████░░   27      ★
LangGraph  ██████████████████████░░░░░░░░░░░░░░░░░░░░░   15
CrewAI     ██████████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░   10
OpenClaw   ██████████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░   10
AutoGen    ███████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░    8

Feature-by-Feature Comparison

| Feature | OpenFang | OpenClaw | ZeroClaw | CrewAI | AutoGen | LangGraph | |---------|----------|----------|----------|--------|---------|-----------| | Language | Rust | TypeScript | Rust | Python | Python | Python | | Autonomous Hands | 7 built-in | None | None | None | None | None | | Security Layers | 16 discrete | 3 basic | 6 layers | 1 basic | Docker | AES enc. | | Agent Sandbox | WASM dual-metered | None | Allowlists | None | Docker | None | | Channel Adapters | 40 | 13 | 15 | 0 | 0 | 0 | | Built-in Tools | 53 + MCP + A2A | 50+ | 12 | Plugins | MCP | LC tools | | Memory | SQLite + vector | File-based | SQLite FTS5 | 4-layer | External | Checkpoints | | Desktop App | Tauri 2.0 | None | None | None | Studio | None | | Audit Trail | Merkle hash-chain | Logs | Logs | Tracing | Logs | Checkpoints | | Cold Start | <200ms | ~6s | ~10ms | ~3s | ~4s | ~2.5s | | Install Size | ~32 MB | ~500 MB | ~8.8 MB | ~100 MB | ~200 MB | ~150 MB | | License | MIT | MIT | MIT | MIT | Apache 2.0 | MIT |


16 Security Systems: Defense in Depth

OpenFang doesn't bolt security on after the fact. Every layer is independently testable and operates without a single point of failure.

| # | System | What It Does | |---|--------|-------------| | 1 | WASM Dual-Metered Sandbox | Tool code runs in WebAssembly with fuel metering + epoch interruption. A watchdog thread kills runaway code. | | 2 | Merkle Hash-Chain Audit Trail | Every action is cryptographically linked to the previous one. Tamper with one entry and the entire chain breaks. | | 3 | Information Flow Taint Tracking | Labels propagate through execution. Secrets are tracked from source to sink. | | 4 | Ed25519 Signed Agent Manifests | Every agent identity and capability set is cryptographically signed. | | 5 | SSRF Protection | Blocks private IPs, cloud metadata endpoints, and DNS rebinding attacks. | | 6 | Secret Zeroization | Zeroizing<String> auto-wipes API keys from memory the instant they're no longer needed. | | 7 | OFP Mutual Authentication | HMAC-SHA256 nonce-based, constant-time verification for P2P networking. | | 8 | Capability Gates | Role based access control. Agents declare required tools, the kernel enforces it. | | 9 | Security Headers | CSP, X-Frame-Options, HSTS, X-Content-Type-Options on every response. | | 10 | Health Endpoint Redaction | Public health check returns minimal info. Full diagnostics require authentication. | | 11 | Subprocess Sandbox | env_clear() + selective variable passthrough. Process tree isolation with cross-platform kill. | | 12 | Prompt Injection Scanner | Detects override attempts, data exfiltration patterns, and shell reference injection in skills. | | 13 | Loop Guard | SHA256-based tool call loop detection with circuit breaker. Handles ping-pong patterns. | | 14 | Session Repair | 7-phase message history validation and automatic recovery from corruption. | | 15 | Path Traversal Prevention | Canonicalization with symlink escape prevention. ../ doesn't work here. | | 16 | GCRA Rate Limiter | Cost-aware token bucket rate limiting

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars18.2k
CategoryAI
Updated2mo ago
Forks2.3k

Languages

Rust

Security Score

95/100

Audited on Jul 2, 2026

1 low