Skip to content
 
 

Repository files navigation

BunClaw

My personal Claude assistant that runs securely in containers. Lightweight, Bun-native, and built to be understood and customized for your own needs.

中文  •   Discord  •   34.9k tokens, 17% of context window

New: First AI assistant to support Agent Swarms. Spin up teams of agents that collaborate in your chat.

About This Fork

BunClaw is a fork of NanoClaw with the following key changes:

  • 🔥 Bun-native - Migrated from Node.js to Bun, using bun:sqlite instead of better-sqlite3, Bun's native APIs for process spawning, and zero-dependency database operations
  • 💬 Discord instead of WhatsApp - Replaced WhatsApp/Baileys with Discord.js for messaging (WhatsApp support available via /add-telegram skill)
  • 📦 Simpler dependencies - Reduced from 45+ npm packages to just 6 core dependencies
  • ⚡ Faster development - No build step needed (bun --watch), instant TypeScript execution

All credit to the original NanoClaw project for the architecture and philosophy. This fork maintains the same security-first, minimalist approach while modernizing the stack with Bun.

Why I Built This

OpenClaw is an impressive project with a great vision. But I can't sleep well running software I don't understand with access to my life. OpenClaw has 52+ modules, 8 config management files, 45+ dependencies, and abstractions for 15 channel providers. Security is application-level (allowlists, pairing codes) rather than OS isolation. Everything runs in one Node process with shared memory.

BunClaw gives you the same core functionality in a codebase you can understand in 8 minutes. One process. A handful of files. Built on Bun's native APIs for speed and simplicity. Agents run in actual Linux containers with filesystem isolation, not behind permission checks.

Quick Start

git clone https://github.com/tobalo/bunclaw.git
cd bunclaw
claude

Then run /setup. Claude Code handles everything: dependencies, authentication, container setup, service configuration.

Philosophy

Small enough to understand. One process, a few source files. No microservices, no message queues, no abstraction layers. Have Claude Code walk you through it.

Secure by isolation. Agents run in Linux containers (Apple Container on macOS, or Docker). They can only see what's explicitly mounted. Bash access is safe because commands run inside the container, not on your host.

Built for one user. This isn't a framework. It's working software that fits my exact needs. You fork it and have Claude Code make it match your exact needs.

Customization = code changes. No configuration sprawl. Want different behavior? Modify the code. The codebase is small enough that this is safe.

AI-native. No installation wizard; Claude Code guides setup. No monitoring dashboard; ask Claude what's happening. No debugging tools; describe the problem, Claude fixes it.

Skills over features. Contributors shouldn't add features (e.g. support for Telegram) to the codebase. Instead, they contribute claude code skills like /add-telegram that transform your fork. You end up with clean code that does exactly what you need.

Best harness, best model. This runs on Claude Agent SDK, which means you're running Claude Code directly. The harness matters. A bad harness makes even smart models seem dumb, a good harness gives them superpowers. Claude Code is (IMO) the best harness available.

Bun-native. Uses bun:sqlite for zero-dependency database, Bun's native APIs for file operations and process spawning, and Bun's fast TypeScript execution. No build step needed for development.

What It Supports

  • Discord I/O - Message Claude from Discord (WhatsApp support available via /add-telegram skill)
  • Isolated channel context - Each Discord channel has its own CLAUDE.md memory, isolated filesystem, and runs in its own container sandbox with only that filesystem mounted
  • Main channel - Your private channel (DM) for admin control; every other channel is completely isolated
  • Scheduled tasks - Recurring jobs that run Claude and can message you back
  • Web access - Search and fetch content
  • Container isolation - Agents sandboxed in Docker with per-channel filesystem mounts
  • Agent Swarms - Spin up teams of specialized agents that collaborate on complex tasks (first personal AI assistant to support this)
  • Bun-native database - Uses bun:sqlite for zero-dependency, fast SQLite operations
  • Optional integrations - Add Gmail (/add-gmail), Telegram (/add-telegram), and more via skills

Usage

Talk to your assistant with the trigger word (default: @Andy):

@Andy send an overview of the sales pipeline every weekday morning at 9am (has access to my Obsidian vault folder)
@Andy review the git history for the past week each Friday and update the README if there's drift
@Andy every Monday at 8am, compile news on AI developments from Hacker News and TechCrunch and message me a briefing

From the main channel (your self-chat), you can manage groups and tasks:

@Andy list all scheduled tasks across groups
@Andy pause the Monday briefing task
@Andy join the Family Chat group

Customizing

There are no configuration files to learn. Just tell Claude Code what you want:

  • "Change the trigger word to @Bob"
  • "Remember in the future to make responses shorter and more direct"
  • "Add a custom greeting when I say good morning"
  • "Store conversation summaries weekly"

Or run /customize for guided changes.

The codebase is small enough that Claude can safely modify it.

Contributing

Don't add features. Add skills.

If you want to add Telegram support, don't create a PR that adds Telegram alongside WhatsApp. Instead, contribute a skill file (.claude/skills/add-telegram/SKILL.md) that teaches Claude Code how to transform a NanoClaw installation to use Telegram.

Users then run /add-telegram on their fork and get clean code that does exactly what they need, not a bloated system trying to support every use case.

RFS (Request for Skills)

Skills we'd love to see:

Communication Channels

  • /add-telegram - Add Telegram as channel. Should give the user option to replace Discord or add as additional channel. Also should be possible to add it as a control channel (where it can trigger actions) or just a channel that can be used in actions triggered elsewhere
  • /add-slack - Add Slack
  • /add-whatsapp - Add WhatsApp (using Baileys)

Platform Support

  • /setup-windows - Windows via WSL2 + Docker

Session Management

  • /add-clear - Add a /clear command that compacts the conversation (summarizes context while preserving critical information in the same session). Requires figuring out how to trigger compaction programmatically via the Claude Agent SDK.

Requirements

Architecture

Discord (discord.js) --> SQLite (bun:sqlite) --> Polling loop --> Docker Container (Claude Agent SDK) --> Response

Single Bun process. Agents execute in isolated Docker containers with mounted directories. Per-channel message queue with concurrency control. IPC via filesystem.

Key files:

  • src/index.ts - Orchestrator: state, message loop, agent invocation
  • src/channels/discord.ts - Discord bot connection, send/receive
  • src/ipc.ts - IPC watcher and task processing
  • src/router.ts - Message formatting and outbound routing
  • src/group-queue.ts - Per-channel queue with global concurrency limit
  • src/container-runner.ts - Spawns streaming agent containers
  • src/task-scheduler.ts - Runs scheduled tasks
  • src/db.ts - SQLite operations using bun:sqlite (messages, groups, sessions, state)
  • groups/*/CLAUDE.md - Per-channel memory

FAQ

Why Discord and not WhatsApp/Telegram/Signal/etc?

Because I use Discord. Fork it and run /add-telegram or /add-whatsapp skill to change it. That's the whole point.

Why Bun instead of Node.js?

Bun provides native SQLite (bun:sqlite) with zero dependencies, faster TypeScript execution with no build step needed for development, and a cleaner API for spawning processes. The codebase is simpler and faster as a result.

Can I run this on Linux?

Yes. BunClaw is Linux-first and uses Docker by default. Just install Bun and Docker, then run /setup.

Is this secure?

Agents run in containers, not behind application-level permission checks. They can only access explicitly mounted directories. You should still review what you're running, but the codebase is small enough that you actually can. See docs/SECURITY.md for the full security model.

Why no configuration files?

We don't want configuration sprawl. Every user should customize it to so that the code matches exactly what they want rather than configuring a generic system. If you like having config files, tell Claude to add them.

How do I debug issues?

Ask Claude Code. "Why isn't the scheduler running?" "What's in the recent logs?" "Why did this message not get a response?" That's the AI-native approach.

Why isn't the setup working for me?

I don't know. Run claude, then run /debug. If claude finds an issue that is likely affecting other users, open a PR to modify the setup SKILL.md.

What changes will be accepted into the codebase?

Security fixes, bug fixes, and clear improvements to the base configuration. That's it.

Everything else (new capabilities, OS compatibility, hardware support, enhancements) should be contributed as skills.

This keeps the base system minimal and lets every user customize their installation without inheriting features they don't want.

Community

Questions? Ideas? Join the Discord.

License

MIT

About

A lightweight alternative to Clawdbot / OpenClaw that runs in containers for security and focused for Bun-native runtime. Connects to Discord, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK

Resources

Contributing

Security policy

Stars

29 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages