I'm still not getting over openclaw's repository speed and a...

Leo Wandersleb

npub1gm7tuvr9atc6u7q3gevjfeyfyvmrlul4y67k7u7hcxztz67ceexs078rf6

hex

deb63ea7b5eb13372c0d028deae0544f8cf3ac7255e252380e207ab18b711eb1

nevent

nevent1qqsdad375767kyeh9sxs9r02up2ylr8n43e9tcjj8q8zq7433dc3avgprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsydl97xpj74udw0qg5vkfyujyjxd3l706jd0t0w0turp93d0vvungha6d6s

Kind-1 (TextNote)

2026-03-03T17:59:33Z

I'm still not getting over openclaw's repository speed and attack surface. The discord plugin alone has 21k LOC and you can't just remove those even if you don't use discord I think. Well, my claw thinks that:

https://i.nostr.build/PZKJmfPnadrE6hCA.png

I'm tempted to dig deeper but given the crazy activity there, I doubt I would get heard if that concern was valid.

openclaw is installed via npm with its dependencies but those dependencies do affect how it runs if you use all the plugins or not. It would be far more comforting if all these plugins needed an explicit npm install openclaw-discord or something.

Raw JSON

{
  "kind": 1,
  "id": "deb63ea7b5eb13372c0d028deae0544f8cf3ac7255e252380e207ab18b711eb1",
  "pubkey": "46fcbe3065eaf1ae7811465924e48923363ff3f526bd6f73d7c184b16bd8ce4d",
  "created_at": 1772560773,
  "tags": [
    [
      "imeta",
      "url https://i.nostr.build/PZKJmfPnadrE6hCA.png",
      "ox 44de951aef6e20e3c9d69b2b83b9bbc239aa58b56e89e3b80a7b709fc153d3cf",
      "x 5e8f086b9618a772ae1af1816e8524bb61fe2057d1a84ce5a095bfb8a2827f65",
      "m image/png",
      "dim 1061x324",
      "bh LJRV|UWBWB%M~qWBRjt7xuWBofof",
      "blurhash LJRV|UWBWB%M~qWBRjt7xuWBofof",
      "thumb https://i.nostr.build/thumb/PZKJmfPnadrE6hCA.png"
    ],
    [
      "client",
      "jumble"
    ]
  ],
  "content": "I'm still not getting over openclaw's repository speed and attack surface. The discord plugin alone has 21k LOC and you can't just remove those even if you don't use discord I think. Well, my claw thinks that:\n\nhttps://i.nostr.build/PZKJmfPnadrE6hCA.png\n\nI'm tempted to dig deeper but given the crazy activity there, I doubt I would get heard if that concern was valid.\n\nopenclaw is installed via npm with its dependencies but those dependencies do affect how it runs if you use all the plugins or not. It would be far more comforting if all these plugins needed an explicit `npm install openclaw-discord` or something.",
  "sig": "9a0dcddc08d782536588bc2de26782c8515510372986f7ae95e567b26aed22059d5ca98dea541c0c931b52a21162cd147284ea21a747090395e4442e781a9205"
}