ClamBot: AI Agent Runs LLM-Generated Code in WASM Sandbox for Security

✍️ OpenClawRadar📅 Published: April 13, 2026🔗 Source
ClamBot: AI Agent Runs LLM-Generated Code in WASM Sandbox for Security
Ad

What ClamBot Does

ClamBot is an AI agent framework that addresses security concerns with existing agent frameworks by running all LLM-generated code in a WebAssembly sandbox instead of using exec() or subprocess calls. The creator built it after trying frameworks that execute arbitrary code directly on the host machine, citing examples like LangChain having a CVE for this approach, AutoGen shelling out with subprocess, and SWE-Agent running bash commands from the model.

Technical Implementation

ClamBot is built on top of amla-sandbox, a WASM sandbox that uses QuickJS in Wasmtime. The LLM writes JavaScript code that runs in a memory-isolated sandbox with zero network access. Every tool call (HTTP, filesystem, cron) must pass through an approval gate back in Python. No Docker or VM is required - it runs as one binary.

Key Features

  • Sandbox Security: All code runs in WASM - cannot touch host memory or network
  • Approval Gate: SHA-256 fingerprinted approval gate on every tool call with pre-approve patterns (e.g., "allow web_fetch for api.coinbase.com")
  • Clam Reuse: Successful scripts get saved as "clams" and can be reused, reducing API costs for repeated requests
  • Multi-Provider Support: OpenRouter, Anthropic, OpenAI, Gemini, DeepSeek, Groq, Ollama
  • Telegram Integration: Telegram bot with inline approval buttons
  • Additional Features: Persistent memory, cron scheduling, SSRF protection that blocks private IPs, secrets never appear in logs/tool args/traces
Ad

Example Workflow

User asks: "what are the top movers on binance?" The sandbox executes JavaScript → makes http_request to Binance API → goes through approval gate → returns result. The bot responds with the top 10 movers on Binance by 24h change.

Getting Started

bash git clone https://github.com/clamguy/clambot.git
cd clambot
uv run clambot onboard
uv run clambot agent

Stack and Scale

The project is built with Python + QuickJS/Wasmtime, contains approximately 10K lines of code, and was inspired by OpenClaw and nanobot. The creator built it because they wanted "an AI agent I could actually trust on my server."

📖 Read the full source: r/openclaw

Ad

👀 See Also

mycrab.space introduces SKILL.md and Prompt Autocomposer for standardized app deployment
Tools

mycrab.space introduces SKILL.md and Prompt Autocomposer for standardized app deployment

mycrab.space has released SKILL.md, a Markdown blueprint for defining app dependencies and configuration, and a Prompt Autocomposer that generates ready-to-use deployment commands from these files. The system enables zero-config deployment of applications like VS Code in browser, personal music clouds, and AI agent interfaces.

OpenClawRadar
Cognithor: A Local-First Agent OS with PGE Trinity Architecture
Tools

Cognithor: A Local-First Agent OS with PGE Trinity Architecture

Cognithor is a fully local, autonomous Agent OS built over a year with 16 development phases. It features the PGE Trinity architecture (Planner → Gatekeeper → Executor), 11,609+ tests with 89% coverage, and supports 16 LLM providers including Ollama and LM Studio.

OpenClawRadar
Free Library of 789 Downloadable Skills for Claude Code
Tools

Free Library of 789 Downloadable Skills for Claude Code

clskills.in is a searchable hub offering 789 downloadable .md skill files for Claude Code across 60+ categories including enterprise platforms, programming languages, and DevOps tools. Each download includes a README and auto-install prompt.

OpenClawRadar
Code Evolution Method Triples LLM Performance on ARC-AGI-2 Benchmark
Tools

Code Evolution Method Triples LLM Performance on ARC-AGI-2 Benchmark

Researchers achieved a 2.8x improvement on the ARC-AGI-2 benchmark using code evolution with open-weight models, reaching 34% accuracy at $2.67 per task. The same method pushed Gemini 3.1 Pro to 95% accuracy at $8.71 per task.

OpenClawRadar