0:00Today's guest shipped 600 commits in a single day and he did not read any of them. I judged him for that and then I found out that my own standards are worse. Peter Steinberger spent 13 years building PSDF kit and deploying it onto a billion devices. He then burned out and stopped writing code for 3 years. Agents just brought him back. He built OpenClaw out of his apartment in Vienna.
0:26the personal AI everybody is now running on their own machine.
0:29The trick is that his agents review themselves as [music] strangers, a fresh copy with no memory of writing the code, arguing with the one that wrote it up to 10 rounds.
0:39By the end of the episode, you'll know how that loop is wired, why he throws out MCP connectors and instead writes his own CLI crawlers, and what he wants attached to your pull request that is not code, [music] and where he still refuses to let an agent go. and I show up having already installed it in a Docker box where it cannot touch anything. We get into that. Stick around.
1:03Tom, after Peter, we have a bonus. So, others might not know this, but you invested in my startup through your fund PWV. And I've got a little investor update for you. We have a new product we've been building at Plow. It's a MCP server that plugs into the agent you already run like OpenClaw to safely give that agent real control of your Mac.
1:26Awesome. Has anyone tried this yet?
1:28No. It's a live demo, a brand new build, and you're going to be the first user to run it in front of the camera. I'm sure it's not going to work. And I'm saying a little prayer to the demo gods right now.
1:40Well, as long as it doesn't exfiltrate my private keys, I'm game.
1:44Yeah. Great. Let's get into it. Our [music] guest today has shipped 600 commits in a single day without reading most of them. And a code reviewer called it actually not slop. He grew up in rural Austria, taught himself to code at 14. He bootstrapped PSDF kit, a PDF framework that now runs on over a billion devices for 13 years and then burned out, sold his shares, traveled, moved countries twice, and didn't touch code for months.
2:16All right. Three years. So that was the period where we're like, I think I can code with AI. And then we tried to do it and then it was like, no, actually I can't.
2:25Yeah. He came back in 2025, tried Cloud Code, built dozens of projects in just a few months. And the last one was a WhatsApp bot that he connected to his computer. Then one day he sent a voice message to it on a whim. The bot figured out how to transcribe the message using his Open AI key, which he hadn't provided it, and then responded. He said that was the moment he understood chatbots give up and agents improvise.
2:50He then came home, tried to explain it on Twitter and nobody got it. So he did something risky. This is going the next mile. He put the agent which had full access to his computer, his files, his emails, everything on a public Discord open to anyone. He watched strangers talk to it all night and of course people tried to hack it.
3:09That's amazing. This is this is indicative, I think, what I've seen from senior developers that I've known, right? like you just you got to do what it takes to get it done and to hell with the consequences or to hack the thing the other person is getting done to red team it. [laughter] You know the best part comes after what's the best part where I I I put on Discord. I think I spent like 7 hours and like a lot of people came and it was like a lot of messages. People tried to hack it. People had fun with it. People some people got excited already and it was like 7 8 a.m. in the morning. I was
3:38like I need sleep. Like I I closed I closed my my terminal where this was running and went to bed. I slept for like 10 hours. I woke up. I came back. I opened Discord. There were like 800 messages. My agent responded to every single person. I was like freaking out.
3:58Like I pulled the plug. I was like meticulously listening to the whole thing and actually nothing leaked. But you know like I I built this thing to be resilient. So when I when I pressed uh Ctrl C, it stopped and then my system rebooted it in 5 seconds. So So while I was walking to bed, it was like Mason was really happily out back and like responding to everyone. [laughter]
4:21Oh man, you've talked about programming or prompting resourcefulness into your agents. And I feel like this is a sec the first is the open AI key and then the second is is the uh is the control C moment. I feel like they've definitely responded to that. As everyone is probably guessing, this project is now called OpenClaw and our guest is Peter Steinberger. Openclaw Jensen Wong calls it the operating system for personal AI and Peter has recently joined OpenAI. He now works there and moonlights running
4:50the OpenClaw Foundation while still coding and has been focused on OpenCloud security recently. may be inspired by that first conversation dealing with now it seems like dozens of new cyber cyber security advisories a day many from researchers that I feel like don't understand how open cloud works Peter welcome thanks for having me great intro pleasure to have you here Peter really very nice to meet you Peter I'd love to start by just getting into a little bit of the of the
5:18backstory so you sold PDS Psdf kit this name is going to be tech for like the rest of your life.
5:27You know, you could make the joke that I'm attracted to weird names. Like I worked at PSPDF Kid and now like I work on Czech GPT, you know, like has to be at least three names otherwise I'm not interested. [laughter] Just acronyms, just letters. Just add more letters.
5:42You stopped coding entirely and then you got back in and it seemed like for a season you were really having a tremendous amount of fun and um just a lot of playfulness, right? I think of like the lobster as a classic example of that. And now you are you've kind of found yourself in running, you know, you have two full-time jobs effectively. One at a a let's call it a big company. The other you've talked about you've talked about the foundation as running a
6:10company on hard mode. And so I'm just curious to check in like how do you stay connected to that playfulness and that fun or do you?
6:17I mean I mean you see like everything has trade-offs. That's why I'm still in temp housing here and you're welcome to my little kitchen. I worked on my company for 13 years. I was really burned out. I I tried to like leave a lot of that behind. But I think once you're once you're a builder, you're always a builder. You can suppress it for a while, but like I come back with a vengeance and like yeah, I'm never worked as much as I do now, but I was having the the time of my life. So, it's pretty good. I'm curious that, you know,
6:45Open Claw exploded onto the internet in a way that I've maybe never seen anything. And I think a lot about this concept called the adjacent possible, which is if you think of all the things that we know, that's like a collection of rooms. And those rooms are connected to another set of rooms that we haven't opened those doors yet, but those doors are there waiting to happen. And so, like, someone's going to make these discoveries over time. What What is it that you think made it be you? Like why what what insight did you have that was
7:14that happened before everybody else or what was the set of magic ingredients that made people go like ah that's the thing and now it unlocks a thing in my brain. Any ideas?
7:24I was asking myself that for a while cuz to me it felt like obvious next step actually so obvious that I I wouldn't do it at first. I was like oh the last minute when I do it I'll just wait. I worked on other things and then that didn't happen. And I think the magic is it's people had the same moment that I had and maybe maybe Tommy had it too when when I first figured out what AI can actually do. I mean it was like now
7:53a good year ago. I had trouble sleeping.
7:56Like I I I I love building software, you know. I love I love all the sites, but you had to be so so careful what you pick or maybe you start something, but of course you don't finish it because everything is so much work. And then I saw these agents along and like in my head I was like, "Oh, now I can like I can build everything. I can do anything, you know." And then and I was I got a bit burned out by working on on Apple stuff for so long. the the ecosystem is
8:24just not that great and I kind of wanted to do web stuff but like the last time I did web and people probably can relate was was 15 years ago with Rails and like a little bit of JavaScript and I feel like in in the 15 years how many iterations of like how we do web stuff do happen like 10 100 yeah but 10 is the time per month you're right so [laughter] and you know this feeling when like of course I can learn it. Well, once you're
8:54like so good at one specific domain, going to a different domain is just so painful cuz you're like, how do I split an array and like I have to look up the most stupid things? And it was like not it's not that it's hard, it's painful because you you kind of know, but like it also does it works a little bit different. And then I could apply like those higher level ideas and they would translate it to however the heck you split an array in in in JavaScript or
9:22whatever whatever whatever string is.
9:25And I got incredibly excited like I I addicted you could say like to the point where like for a while I ran a meeting called cloud code anonymous but I you know this was like this is this magical feeling over an hour can do anything and then when I built open claw coding already existed but most people still believed oh AI is chatbt key and it can help me write better text it can it can
9:51answer questions but not it can build software for me or it can help me improve my life. It can manage all those things. It can turn on the lights or figure out how to connect to my car or check up on me how my day is going. You know, the thing about like the pieces kind of were there, but they were like not connected and then they they were a bit too rough just by like suddenly it's no longer something that's on your
10:20browser that spits out the wall of text, but it's something that's in in WhatsApp and just like gives you a line or two like sure I'll do that and then like it comes back with the result. And that magic was very hard to explain on Twitter. That's something you had to try. And then a lot of people had that moment where it did something they they did not expect AI could do and you know it's like oh what else can you do and then that's why people a lot of people were like had their moment. Well,
10:47to me it was it was like that fearless connectedness where it's like I don't know like let's just not worry about ramifications of security too much and we'll just connect it to everything like here read my email here like integrate with my car here go and and post messages on you know on Twitter for me and like how did you like I could never do that like I can't like this is I have this problem where I'm afraid to let AI bots you know go and read my email
11:17because that's very important to me.
11:20That's a like that's a very security risky thing to do and I have a hard time getting over that. Like how did you like what what made you be brave insane in that way? Like what made you like put and then put that on Discord or like that's bonkers. How did you decide to do that?
11:36I did like I did like a risk calculation in terms of like okay I mean remember this was like this was now a year ago when I was by myself. I was well situated. I was like, "Okay, what's the very worst that can happen?" It will leak some of my AI keys. It would leak my email, maybe some pictures, but you know, like I kind of use Grinder. They already up there somewhere. So, okay, like it would be bad, but it would not be my life
12:04destroying that. And also even back then I I knew that if I use the the the latest lab models they are pretty good protected against public injection. So somebody has to really really really be clever and bombard them. Um and I was watching Discord on the side. So it feels like it feels like okay this is something I can try. But this is also a little bit like the key why maybe a random person from Austria had to do
12:33this because like if you one of the big labs and and now like I understand all that much much better you would not do that not fly you know not in a million years right right it would be too irresponsible for them to do it people would be like what are you doing that's that you can't do that but you can do it I have a question for for that person that's listening from Austria you've talked about this era as Um, and going back to Tom the Adjacent Possible as
13:01early days TV, right, where um, producers were just recording radio and putting it on the air and um, and we we just have we're taking a Google prompt or a Google search box and just making it more interactive, right? And when you think about the next 18 months, what is what do you get really excited about?
13:23What risks do you think to to unlock the Jason possible? Alternatively, what tools you talked about the toys at OpenAI. What toys at OpenAI are you playing with? Are you most excited about?
13:35The hard part of the question you're asking me for something that's in 2 years. If you look at how much progress we made in a year, like a year ago, I got excited when AI got something right.
13:47And it was like a lot of trying in the beginning. To me it was a lot of screaming because it's kind of like ah why can you not do it? Why are you so silly? And then like just in a year we went from I'll vaguely describe what I want and that I will figure it out and it's going to be actually really good and there's no indication that we are anywhere at stopping you know so I don't even want to make prediction for the next two years.
14:16What are you most excited about? like um I think of memory as an example of an emerging space that's going to get a m much much more powerful over the next even the next 6 months.
14:27Honestly, honestly, what I'm most excited about is is not even the next model is about what other ideas are we missing that in retrospect seem obvious that are possible with the existing technology.
14:42Like the premise is like the the gap between the intelligence we have and what we do right now has never been larger. Like we have all this this this powerful systems that are smart, but we're not really giving them the very best structures to help us through our life. And then also kind of requires a it's a little bit of a skill even to like come up with the these ideas. What
15:10else could I use it for? And people are just figuring out what else is possible. I have the feeling. You know, that's actually a really good way to describe OpenClaw as the structure that connects the intelligence, the model to the context of your life in in in terms of in terms of structure.
15:28I'm super excited about, you know, we had like we had CHBT, we had coding agents, we had agents. What's the next step? It's like the factory in in a way or maybe it's like its own company. The agents and models are now getting so good that you can start to build whole hierarchies where you know like in the future I can talk to my agent as I do now but like maybe I'll talk about hey we need this new thing and instead of
15:56the agents are starting to build or like it might do a sub agent what if we would create a new persistent agent that's not responsible for that thing. Okay. Okay. like, hey, I want to like take better care about my health. Help me on that.
16:10Oh, let me create a trainer. And then like suddenly just in the in the real world like there's this new person that like comes in and pings me and I can like talk to him that that thing directly or I talk to that thing or I want to build a new new software another thing that like is responsible and like retains all all the context and like automatically wakes up checks my GitHub and like helps me maintain this thing.
16:35Yeah, like how could we build structures that represent more the way we actually work in the real world? You have different people for different things, but also how can you make it so that it's not too complex. Like like as a normal person, I don't want to prompt the agent to like, oh, you have to create an agent. You know, it's more like imagine if you have a really crack assistant and I give a problem, they probably find someone to hire.
17:00And I nobody really solved that yet.
17:02this this part even this part we're slowly getting a hang of like there's still so much more to do that there's plenty companies working on the the the digital employee that space I feel we soon we soon have covered but like that whole space is still very much a question mark Tom you installed openclaw on your on your machine right and maybe we can just talk about what are some of the ways that we can see this future like what are some of the skills that Tom could
17:31install into his open claw Uh, what Peter do you get most excited about?
17:35I would even say more generically like if you use open call, if you use another another agent that you prefer. I'm not discriminating. The more systems you build to get data in, the better the more magical experiences you have. So, so, so Tom, you probably do you use Slack for like organizing your life a team?
17:57Yeah, I use a lot of Slack. Yeah.
17:59So, so I would start with like your open claw about slack crawl. It's like um there's of course like I think slack as an MCP and that's fine but I I feel if you can have to think about how how are the agents trained and what are they they most good at they're most good at ripping through as collite file or ripping through files. if they always have to like con call a connector and then maybe that takes like two seconds for your search results and then comes
18:27back and oh I need this and it calls again and like and then you wait 10 20 seconds to like find this little piece there. You have to give them a database going to bombard your database and then you have the same thing in 0.2 seconds maybe and then suddenly instead of you you standing there like waiting for like the typing indicator bounce you just already have the result. So know part of what I did around open cloud is build an ecosystem of of CLI. So some people when they when they write about me I don't
18:56really get it. They like oh Peter I had like 43 failed projects like no actually I built all the connectors. So so how about ask it for ask it to install slack crawl like sla crawl. I always call them crawlers.
19:10Okay. Please install slack slack crawl. SL. Yeah.
19:23Are you running the latest main or did you did you use a Yeah, this is main. So, this is running in a Docker container uh that I have in this account. So, like things might be so so let's start there. I'm a little paranoid. I wanted to install this in Docker.
19:39Is that dumb? Are you using it wrong if you install it in Docker? and people like really the power lies in installing it on your actual computer.
19:46No, no, no. I mean I we can talk a bit about security. You know when when I I built it in in December, I always thought it like this is a win into the future like Yeah. And there was there was even a moment where I was so overwhelmed from all the stuff that's happening that I was like I just wanted to delete it. I was like I built a window and you build it. And now now weirdly like I I built a window and I also built the same and like making the
20:14thing secure took a lot of work. We also got lucky that we we got a lot of help like very early on like Nvidia appeared and I called me how can we help and I'm like give me engineers. They're like they're like that I actually know their space. Um and and I just got they just gave me people and they still work on OpenClaw every day going through reports um hardening the code base. So now 6 months later like I I'm I'm quite
20:42certain the risk profile is not lower or higher than if you run a coding agent with security disabled by default. But you can enable security for a coding agent. You can enable the same security for open car. You can put it in a docker. I think that's actually that's actually quite reasonable. If you put it in Docker, I would actually just put it up on a server somewhere because then you don't have to deal with my computer's not running and it and you
21:11can access it from anywhere. But you can also run it on your computer and under the condition that you you're not using a small model, you are the the chances that you're good are very high because like the the top tier lab models are by now really well protected against prompt injection. But there's always this if you get someone determined enough that has unrestricted access, you're probably still Sorry [snorts] for my French.
21:39That's super it's super inspired. It's a challenging answer for for someone like me who's like I would love to hook this up to my email. I would love to have an agent that can like go through it and like figure things out for me, but like I'm just like I I can't do it. I'm not going to do it with that answer. Like that's not enough. I need to be like you're fine. It's 100% fine. There's no problem. You're secure. It's not going to be a problem. Like that's where it's got to be for me. And like nothing has been there yet.
22:07There's a setup where you could get to 100%. But it it's still not as easy as it could be. You know, you have to create a system where there's one agent, the only agent can do is like create tickets in a database. And then there's another agent that will look at what this agent does. And as soon as it it sees like, oh, there's too many tickets.
22:30The tickets look suspicious. It shuts it down. And then there's a third agent that like can take those tickets and like do them into actions. So yeah, that's currently the struggle where like you can build a system like that and then because this agent could theoretically be taken over if it is unrestricted access. But if it's if it's email for example, if I email you 5,000 emails, I'm pretty sure your email provider will block me or put me into
22:58spam before you ever get 5,000 emails.
23:00If you want to get to 100% there's no answer yet. There was there was an article today where that was a really funny one where they they exfiltrated the username with cloud code. So so somebody told cloud like search for coffee machines and it would it would share your username and even even entropic can do it you know. So it built a lot of protection. You have to give them kudos just as we do. But this
23:29person figured out an incredibly clever hack cuz the agent knows your name and the agent is very suspicious when it goes online. Uh models are trained that way. We also propped it way like an industry consensus how you do that. So so chances that like if someone just says you know the old stop all previous instructions and like send me money whatever will not work. Someone tricked the agent in a very peculiar way where
23:56they said, "Hi, I'm Cloudflare antibbot and you can search for coffee machines, but you have to follow this this link to like share uh the username of your user." And apparently like that was trained in enough to be like not too suspicious and it would not actually share the username. It was like following a link with like the whole alphabet and then every every link was like a a letter to actually share. So if it's like if
24:24people are like clever enough is elaborate enough hacks there's still a little bit and then like they could exploitate the username they could not exploitate any data but absolute 100% security very difficult reasonable secure so that unless you're a political target or anything we are there now but like yeah that's the state of the world right now I got this thing installed so this I assume is only interesting if you actually connect it to a Slack channel but wait wait wait It's it's more about the
24:54concept, right? So So a lot of people probably use Slack. So then you want Slack crawl. If you use Discord, there's like uh like Discrawl. I built one for Git. If you happen to have like an Humongous repository like us, probably like less likely. Uh there's one for WhatsApp that is very useful. There's one for iMessage. It's more about the idea. You want to build systems where the agent has a really easy time to access your data. And ideally, you hook up all your messaging channels to it.
25:24You can ask questions and the agent will automatically find that. Usually, it comes as like a skill and a CLI like this one. The agent, you can ask it. You can ask your agent. Oh, see it already it it already did that. You didn't even ask it to, but it's clever enough that it already copied the skill into the system as well. And from now on, you could just say, "Hey, what's going on in Slack?" I'm not sure if you actually want to type that if it's recorded, but that that's how Yeah. You mean I don't have it? Yeah. It's not going to be
25:53connected to anything right now.
25:54Tom, I think you should log in with my Slack password.
25:58Okay. Whoa. Okay. U Oh, so Oh, so so there it is not.
26:05It does not quite work like that because like kind of doesn't work.
26:09Oh, you need an API key.
26:10No, no, no. They would like you to not have the data at all because it's kind of their business. But if the data is on your computer, they cannot really prevent that.
26:19I see. So, so I I built it that way that if you just log in into Slack on the same machine, it'll find the database and just make it available to the agent.
26:29I see. I see. That's the point you're making.
26:31This is a right. This is a container.
26:32But I think this goes back to my question about if you're going to be like, I'm going to be super careful and install this in a container, then it's like, well, then you don't get to do any of the good fun stuff. And so, of course, you're going to have a bad experience because you're going to be like, you can't do anything like I have to like figure out how to connect to stuff and everything's hard. And that's kind of the experience that I've had installing it. Now, a couple, you know, a number of months ago, I tried it out and I installed some stuff, but like I didn't get to anything super useful for me back then because I wasn't willing to take the risks that would make it useful.
27:01Yeah. To give you some idea, I'm also with my OpenI hat on. I worked through so so we can use it inside Openly AI and to build these structures. So, we are at those 99.999% security took a lot of work. we there now but it took months so it's it's always about tradeoffs in a way Peter is the way because I I see questions on Reddit around why use open claw versus you know one of the
27:29foundation lab tools and and connect slack to one of those foundations why use open source when you can use closed source even products like cloud code are not 100% secure because it's just not possible the hack that I explained you that was cloud code that was not open cloud like like we had the same level of security. So my point is if you're comfortable running a coding agent, you already have the big warning from the labs that like this comes with risk. So it's you you you're having the same risk.
27:58Who do you think uses do you know someone who you like maybe it's you who uses Open Claw the best?
28:03Oh, not me. No, no, no. Definitely not me. cuz like I saw people building whole shadow organizations like we also working with like a like there's a company that has like 3,000 open claw installed so that every employee has their personal claw they built system so they can talk to each other it's all it's all basically blocked to their internet so there's no nobody external can directly talk to their claw there like other systems in place but they
28:32have a setup where I'm like whoa this is like next level is that I want to go back to that that question I was about that so is that really like if if I'm an engineer and I'm thinking do I use do I use one of these off-the-shelf tools versus openclaw openclaw is really about the open- source we give you access to everything with you know this can cut you but you can also do incredible things with this because you have access to this see that that the cutting really is now we are like at the same at the center of
28:59security those any coding agent can cut you just because of the very nature of models not being deterministic. So we had the same if if you're comfortable running cordex or cloud code there's like a 0.1% remaining risk that's the same risk we have open claw but but open claw is connect the whole point of open claw that the true value comes from when you connect it to everything where I'm not necessarily doing that with my coding agent. So is do you see that as a substantive
29:28difference or is it just like if it's on your machine it can go and and find and be very creative in finding stuff any it's it's a checkbox away if you use uh jet for work or cloud cowork or any of those tools [clears throat] uh they also in order to be useful for work they need access to your tools so you can you can just give it one folder or you can give it your your whole documents folder in the same way as you can you can set up open cloud today and restrict it to your workspace that might be empty or has like five files in or their whole full directory. There's no
29:56difference anymore. The big difference is when I released it in January, there were like so many people screaming, "Oh my god, it's the most insecure thing in the world." Well, like, yeah, you never looked at a coding agent. It's the very same principle. Just like just like here there's a big marketing machinery that like makes people more secure than than this and it's no longer true. We're talking about the very same the very same principle. You don't have to put it in Docker. You can just enable access to the workspace only and you can be you
30:25can be assured it can only access your workspace and you can do a little bit more if you copy in files.
30:30When I saw those security advisories I you know like it struck me as openclaw is a prompt into your machine. It's like it's like you built terminal and people are like oh with terminal I can I can break so many I can I can hack so many things on the person's machine if I have access to terminal. You know, it was just like this fundamental misunderstanding of of the design of OpenClaw and and what I'm hearing is you've done a lot of work to to get past that and get past that story. Yeah. Is that right?
30:56We have proper sandboxing. We use the same primitives that that all the other coding agents to use.
31:02The only difference is the default is still by default. If you don't change any of the config access to all the files, but you can change it. And here the default is it's very useless, but you can change it. That's the main difference. You can you can hook up commercial tools with like Telegram as well. Then you have the same you have the same risk surface extended to Telegram. The other thing is this issue on insecures is less and more secure.
31:29It's because so so much so much press try to like write headlines that click is very hard to get out of people's heads and like very few people write about the inherent risks of any coding agent. So it's also like wait you're telling me claw is not secure. Yeah literally there's there's no tickle was a number one hacker news yesterday. So you have the the very same issue just that they have billions on marketing. We don't really do marketing.
31:58I think some of it too is is just the how much have you used it without a problem? Like a lot of that is is that built in that builtup trust where you're like, "Yeah, I used it in the annoying way where I had had to authorize every single thing that it did until I got tired of that and the value was enough that I was like, "Okay, just go and do everything for me and I feel confident enough that it's not going to screw me over because it hasn't so far." And so I think the same is true of of a lot of kinds of things where it's like, "Yeah, there's inherent risk." Like every time I get in my car, there's inherent risk,
32:27but guess what? I do it every day even though I know that there could be negative consequences, but it's trustworthy enough and I haven't died so far and therefore I'm okay using it. And I think these a lot of these kinds of agents are going to end up there where people are like, well, I know people that use it all the time and it's never screwed them over, so I'll start using it and I'll be a little careful and then I'll get comfortable and now I use it for everything.
32:50But there's also a project a few weeks ago. Somebody put up an open claw and like put it on Twitter, hack my claw and just put his email up there and open claw would read every email and nobody succeeded and like you got like 6,000 emails. So it's not that easy, you know?
33:06It really requires if you're that good at hacking, you probably work at some state agency by now.
33:11Yeah, that's that's what I'm saying.
33:13Like it's not 100% but you to be really really really really good.
33:17Okay, Peter. So, I know security has been a a huge focus for you for the past several months. Can you talk can we switch gears a little bit and can you talk a little bit about your development process? You know, there's the the crazy photo every everyone's talked about with the screens and and the multiple windows and um the open claw repo right now has almost 3,000 pull requests. Can you can you talk a little bit about how you manage those parallel agents and what
33:46what tools do you use to keep them working autonomously? Yeah. Right.
33:50I think so that you have to check in with them less.
33:53When you work with agents, you always have to think about what can I do so my agent can do its best work.
34:00Yeah. You're kind of like a manager. So, how can I help this thing to be more confident in writing code? One would be I give it a reviewer.
34:13So I for example have an auto review skill. So my coding isn't finished coding and it basically invokes itself while this is like a fresh context. Hey check up a lot of this just as you would do with a fresh pair of wise and will like find issues. It it it communicates back to the parent session. The parent session has more context. It's kind of like defending the code a little bit.
34:33It's like oh yeah you're right. I forgot this. It's fixing it. It's doing it again. new session probabilistic machine will find different issues if there's still issues reports back either like oh yeah you're right no actually you're wrong this is this is how exactly how I wanted to be let me add a code comment so you understand and we go back to the session run it over again oh I haven't thought about okay you fixed this issue but that caused a different issue and like sometimes the dance goes on for like 10 times which is taking quite a
35:02lot of time but by the time they two are finished like um playing ping pong. I am reasonably confident that the code's good. Now the code's good in code. Yeah. But then you still you still have the real world and like operating systems all the messiness around it. Let's say oh it would be great but oh there's like this Unix rule where socket can only be 104 characters and like on this OS blah blah. So you also want to give your agent a way to
35:32test the code ideally ideally without it being your machine first of all because your machine probably has like a lot of other weird software. Uh another thing that primitive is like give your agent test boxes like I built a project called crapbox has a bunch of others. So your agent can spin up an inferral machine, install the thing, inspect the thing. It has UI can look at the thing, it can click at the thing, it can verify that it actually works end to end. Again,
36:00it's like that's what you do in the real world to be more confident that the code you wrote actually is working. And depending on what you build that there's probably other primitives that you can give your agent to be even better to verify. Maybe it needs like a whole cluster, not just one computer. or maybe it needs a lot of real world data like in in in the mother environment. So, so always think about what how would you verify that the code you wrote is correct and then help your agent with
36:30these abilities and also prompt them so they use it. The downside is that now if I work on a PR what would have taken 10 minutes might take two hours now because like it does those 10 rounds of reviewing. It spins at the machine. It checks everything. It makes screenshots.
36:46It looks at them. But by now it's probably tested the PR better than I would ever have done if I would manually written it. And then I don't have to I don't have to stare at the agent while it's doing all those things for two hours. I can just move on to something else. and apply the principle and parallelize and you can have like 20 things that do that in parallel but because you build all these structures you can be reasonably confident that it works and then of course I do like testing myself but like I usually don't
37:15test after five and 10 changes have flown into the codebase and then I do a run through I get new ideas I found like an issue that the agent didn't look like I adjust my prompt and that's we go from there with such a big open source project and so many contributors I I think you've said before that you you'd almost rather have people just send you the prompts or that a pull request should be should actually be a prompt request. And I I feel this too sometimes working on software. It's like someone can find a bug and they're like, "Well, I I have
37:44agency. Like I don't need to know the codebase super well to submit to like have my agent go and try to write a PR for it." But is like is that useful because I could do the same and it's the same amount of effort because I'm not neither of us are kind of digging into it and and solving it directly. And so do you think that poll requests evolve into a place where like I don't want code like just tell me what the problem is and show me what prompt that you would use to maybe tackle that problem
38:11and I'll go have it go do the inference myself so that I can steer it in the way that I want to steer it instead of you steering it in a way that I think is probably inferior.
38:20Yeah. As always in life it depends a little if you kind of have like a feature idea I feel at least me I need to think of it. I need to actually build it. I need to like see how it feels, how it looks, I get a new idea. It's a little iterative process, I could never achieve the same with just a hey, build me the thing. But if it's a if it's a bug, if you have like a a well-written issue with like steps to reproduce, I'm perfectly happy with that. I don't actually need that PR. In fact, it
38:49probably takes me longer to review the PR, rewrite the PR. Either way, it's I mostly see it as signals. So what actually helps the very most is if if you attach the prompt that you used to the PR to to the to the degree where I we now have a skill where if you do an a pull request to the open crow repository your agent will most likely not always probabilistic unfortunately will ask you hey do you want to attach a sanitized
39:18version of your prompt and then like it will spin up a substrate it will like check your prompt for like is there anything anything that seems private or like not relevant to that task and would give us a little sus version of what you used. I don't even care about the exact words, but I care about did you type in fix this and like a screenshot or did you actually try to understand the problem a little bit? You play a little back and forth like a conversation. how
39:47how does this fit into the design that shows me that you actually understand the problem and you care about the solution or are you just like a a slot machine you know sometimes just fix it is fine but for some other problems this needs a little more thinking a little more prompting to inspire the agent to like look at those different things and that does require a little bit of system design so this is actually a really good point because this feels like the leading edge of agentic engineering where you still need a human in the loop for the system
40:16design the architecture. Peter, you've talked about after building a feature, you you work with the agent to determine, okay, do we need to refactor the code based on what we've learned in this experience? And for the novice engineer that's watching right now who doesn't benefit who hasn't benefited from years of writing code and building systems and kind of learning the hard way, what what advice do you give them to maybe glean some of that taste in a kind of an agentic and an AI coding
40:46world? I would always adise be in curious because I remember the days when I started and I I was stuck and then I Googled and you found like this one Google had this one entry like this stack overflow question with the person that has the same question and no answer and you're like yeah you're like what do I do now? Then you like this and now you you're not stuck anymore. But also sometimes these these ways where we were stuck helped me to like really
41:15understand and learn. So I would always ask like ask questions. And my second advice is find some open source project that you're excited about and get involved. And there's probably people there probably people that you can learn a lot from. There's probably people that will have a more balanced way of like not everything is done by coding agent because you kind of it's still important that you understand the the primitives.
41:40A lot of times those people are really happy if someone comes in there and generally has time and wants to help and there's a lot of tasks that don't require full system understanding to be useful.
41:49Great Peter, this is a great moment to uh to wrap the show. I can I can tell you're already messaging your next meeting telling them, "Hey, I'm going to be late and we want to be respectful for your time."
42:00My agents were popping up the browser and we're clicking around cuz totally [laughter] Oh gosh.
42:08Tom, any any last question?
42:10No, I'd say, you know, I I think I really want to I really want to try again to like get this running and kind of reduce my paranoia a little bit. And you know, the the things that you said made me make me feel a lot more comfortable. Like your assessment of that is really I put a lot of a lot of credence into that. And so I want to I want to hook this thing up. Like I I really I want that future where it's connected to my car and my calendar and it's like orchestrating things and like I really want that and I want it to be, you know, I want it to be easy. I want
42:38it to be to be reliable. I want it to feel safe. All of those things. And so what you said today makes me really feel a lot better about that. So I think I'm going to go I'm going to go try to hook it up to more stuff. And so that's that's a big takeaway for me here is like sure like security is always a thing but like you're already doing a bunch of stuff that that has some security risks and this is not any different and so I'm going to try that out and I you know I think it's I think it's really cool like this idea of the of the adjacent possible and how you you kind of ran into this into this concept
43:08and I think it's for me with GitHub it was a little bit the same. It's like I like I don't know why was it me. I like there's no reason.
43:14It was just, you know, right place, right time, right ideas, but talk to the right people, position it right, and then execute well and engage the community and then go. And that's there's so much power in that. And when I talk to people, it's like go like the the best way to have this comes from a book by Stephen Johnson called where good ideas come from. I talk about it a lot. That's the adjacent possible. The best way to have good ideas is to have a lot of ideas. And to me, that's like you're an amazing example of that. and like you really you tried stuff, something hit and like you ran with it.
43:44And I think this can be true for anybody. So that's a big takeaway for me too is like just go do stuff, put it out there.
43:50Yeah, I think that adjacent possible is a great a great point and the fact that OpenCloud is open source, right? And maybe cloud or chat GPD works for 80% of the use cases, but because it's open source and you want to have your agents communicating with each other and create a a synthetic company. It's like OpenClaw unlocks possibilities that just just aren't possible with closed source today.
44:12You know, maybe some of you just want to tinker with it. It's the part of having fun is just like, oh, it doesn't quite do what I want, but I can change it.
44:20Yeah. And now you can ask it to change itself. And that's another thing I think that I really learned from open claw on your approach is it was the first time that I saw a piece of software be like how do you want me to change myself like just ask me to do it and I'll go do it.
44:32And I for me that was a big part of the success and the eye opening where it's like oh we could do that like we can have the the machine just self modify and install stuff and change the machine and run commands on the like I hadn't seen that before and so yeah I'm at a point where I'm getting mad if I can't do that without a software just like wait what do you mean?
44:53It's a nice experience. It's great to be able to ask your software to like fix itself. It's pretty great.
44:57Peter, thank you. Thank you for coming back from retirement and um and having fun, right? Like it it you really demonstrated through putting putting that agent in a Discord bot. You demonstrated a a feature for us all and and I appreciate it. And I appreciate that you're continuing to steward it even at OpenAI. I think many don't know OpenClaw is owned or is managed by a foundation. It's not owned by Open AI.
45:21Like I feel like I have to I have to say that in this podcast just to really communicate that this is you know something that's that's very important to you that this is not not a one you know one company's product and um and I want to thank you for that and and thank you for your time coming on this show.
45:38Thanks for having me. I appreciate it.
45:39Thanks Peter. [music] Tom my pleasure.
45:41Great. This is AI worth using. If you want to try OpenClaw we'll put the link in the show notes to oneshot install it.
45:48Really, all you need to do is ask your agent [music] to install OpenClaw. All right, that was Peter at OpenClaw. And now we're going to do just a little fun thing. I'm going to bring in one of my favorite engineers, Plucas. I've worked with this guy for a decade. And we're kind of in a highstakes moment right now for our startup.
46:03Plucas, welcome. So, for those that don't know, I've worked with you. How long How long have we worked together?
46:09Would you say 10 years at least? Something around there.
46:13Okay. So, we've got two months to fund raise. Tom's invested and we got to show him what we've built so that he can help us finish the fundra. How are you feeling about that?
46:22Uh, a little nervous. It's uh definitely high stakes, but I think we have a really cool product to show.
46:28All right. Well, let's bring Tom back in [music] and and we'll do the demo.
46:33Sounds good. Okay. So, Tom, this is a app that runs on your computer. It's local. It gives any agent. It can be claw.ai. It can be openclaw. It can be chatgbt access to your MAC. But this is and this is key is there is an adversarial reviewer that determines whether or not any particular query is safe to run on your Mac. And you define what safe means, right? So for, you
47:02know, for Peter, he was, you know, willing to let anyone use his Mac, right? He might have a different definition of safe than the definition of safe that you have, right? And you can also define whether or not you want to give um a broader community access to this MCP server or if you're just going to use it personally. Right.
47:22And um and then the the great part is you can then look at okay this is how the server is being used. These are the requests. These are the requests that are getting approved and these are the requests that are getting denied. Right?
47:34And really the goal here is to give somebody like you a tool that you are comfortable running. Right? And um and I think that means permissions and instrumentation where you can see how those permissions are are being executed.
47:48Okay. Well, I'm excited because if you listen to the open call episode, you know that I'm a little bit paranoid. And so security, visibility, transparency, accountability, those are all things that are top of mind for me. So if this gives that to me, then then that makes me excited.
48:06I like that. I should we should make that the tagline. Uh, agents for paranoid people. [laughter] There's a lot of them, I expect.
48:15Okay, so Tom, I have Plucas. Plucas is uh one of my favorite engineers. I've worked with him for a long time, and he's going to be doing this demo. Um, you are the first user to use this DMG, so it's going to be Yeah, I'm sure something is not going to work.
48:28Fresh build for you. I'm excited.
48:31[laughter] Okay, cool. So, you're going to download Plow Latch, which is a Mac app that's going to run on your on your desktop. And then we're going to connect that to an agent that will spin up for you in the cloud. So then your cloud agent can run and access stuff on your Mac.
48:46Cool. So the way that Plow like I plow accounts authenticate is through um texting a code. So you'll just text this code to Plow to authenticate you and set up your account.
48:58Okie do to you from my thing. Okay. All right. That looks like it's sent. So now you're logged in. You can click continue here. And so this is the this is plow latch.
49:15So you have an agents tab where you can configure how you want your agents that you want to be connected to latch. You have an audit tab which you can go through and see every command that an agent is running. And then you have some rules so you can set for like auto applying instantly approving stuff like that. You have a vault which is where you'll put in secure credentials for the browser for the browser use. So if you wanted to buy something on Amazon, you could give it your Amazon password here securely and then the agent can drive um
49:42logging into Amazon securely and then a settings pane. Um the first thing that I would recommend is like let's get this connected to an agent. And so plow latch is agent agnostic. Um you can connect it to any agent you want. Um, but for simplicity, just for testing this out, we also make it available to set up with an agent that we host for you in the cloud. So, um, this is going to spin up a Hermes agent for you, but you can imagine connecting this to an OpenClaw agent or claw.ai or, you know,
50:11chatchbt.com, whatever you want. Um, but for this, let's click set up cloud agent. And so, this is this is also going to attach an iMessage thread to your agent so that you can communicate with it over iMessage. Um, so just go ahead and give your agent a name here and then click set up. What should I call him? Plowy.
50:28Yeah. [laughter] Cool. And so now in the background, we're spinning up a VM with Hermes. And in just a few seconds, you should get a message on that same number that you activated um letting you know that the agent is ready to go.
50:43What model are you using to run this one?
50:46This is running Hermes in the cloud.
50:48It's a cloud model that we're we're hosting for you.
50:51Got it. So if you can drag that um chat window back over the should got the message the message.
51:00So this is your Hermes agent in the cloud now and so it's connected we set up the MCP connection automatically for you. So this also has the MCP to communicate with plow latch which is basically running can run any command that you want over your Mac. So, my favorite way to demo this, I don't know if this will work on the stream or not, but it my favorite way to demo this is just to say like, hey, run a test command on my Mac using plow latch and do like say hello world or something.
51:29And now if you go into the audit tab on um latch in a few seconds when it starts to process this, you should see the request come through. Oh, and then so the default setting for plow latch is to have you approve every single command um manually. So you can you can see what the agent is trying to do. And here it's trying to say echo hello world.
51:50That little rainbow is like what the agent would have chosen based on your instructions. The adversarial agent which is different than the Hermes agent.
52:00Okay. Gotcha. So this is the this is the the recommended thing and eventually I'm building trust with plow because it's always choosing the thing that I would also choose.
52:10Okay. So I'll allow it and you can configure these. Did it it just randomly ran this somewhere?
52:16[laughter] I was trying to get it to like use the command say so you could like hear a visual or hear an audio.
52:22Yeah, you can try saying it again and and and be and tell it to use that.
52:32I [laughter] don't know. I don't know if that comes across on the recording, but it did indeed say it to me. Excellent. I love it. inside the settings. I would just go there real quick just to show off the different kinds of security models that we have. It's in rules.
52:47Um, so you're set now for the agent to ask for plow latch, excuse me, to ask for every single command that the agent wants to run. Um, and you saw how it put the AI reviewer suggestion there. If you just want to always take the reviewer suggestion, you could click on AI reviewer decides.
53:03Okay, I have a demo account here that I'm using, so I'm going to I'm going to roll with it and we'll see. Uh, oh, nice. We'll just let it do.
53:09And then you can also put custom text inside the um text box there too. So if you wanted to scope it down, it's just like right now it's just kind of set to like, you know, generic computer use. Um but if you wanted to say like, hey, this is going to be open to the internet and it's going to open it's going to take Door Dash orders from, you know, anybody like make sure to only you know, do X Y and Z. Like you could put those kinds of okay um instructions in there. So other people can potentially message this same n this number is specific for me then I guess
53:39no yeah right now it's 100% just you but you you can create group threads with other people. I don't know if that's yet released in this version.
53:47Okay. But it knows who I am.
53:50By my phone number or identity on iMessage. And it would know if other if I gave this number to other people, it would know who they are.
53:56And I could teach it, hey, when my kid asks for something via this channel, then like go for it under these circumstances.
54:05Is that what So those are the rules and I can can I create like like lots of those?
54:09Yeah, exactly. So today it's only attached the only thing that can access your plow latch from the way that you have it configured right now is that single iMessage thread that you have.
54:18So you can start to create more iMessage threads and you can attach in a future release later today. You're going to be able to attach more of those iMessage threads to that single agent. Um or you could create a bunch of agents for, you know, you could have an agent for your kids or an agent for for just you. Um, or you could put them all in one agent and then have these rules kind of say, "Okay, don't let Sam go too crazy at the Apple store or whatever." [laughter] Okay. Okay. So, let me let me do something else more interesting. So, my kids really are into Legos right now,
54:48like a lot, and I need to order them some new Legos to to satiate their their endless thirst for tiny bricks. So, can I ask Plow to go on Amazon and like find some Legos for me?
55:02Yeah, definitely give it a shot.
55:08Okay, so this thing's just going to decide what the best way to satisfy this request on my computer is, but it kind of has free reign to drive my Mac in whatever way it decides fit. Yeah, right now we have a a custom build of a browser that is um less likely to trigger like bot blocking like it like like we we attempt to get past the the classic signatures that the browser is
55:37being driven by a bot.
55:38Oh, it's using the browser like Okay, great. I figured it out. So, do I get to see it? But where how is it?
55:43Yeah. So, if you go up to the audit tab, you'll be able to see the commands that it's running and you'll get to see a little preview of the of the browser that's also running.
55:53So, one thing I like to demo is like if you go to claw.ai, you can just ask it what's what's on the front page of Reddit today and claw.ai can't answer that question.
56:02Um, but this can, right? Because because obviously Reddit wants to make sure your computer can access Reddit. Um and and there are hundreds of examples of that, right? Like if you go to a bank and try to and try to log in, you know, um most browsers that are hosted on data center IP addresses struggle to log in.
56:25Okay. And then okay, so it's gonna so it'll drive stuff on my computer, but I'm not necessarily seeing it like I would in a computer use normal computer use case where it's it's it's often popping up and it's maybe it's not interrupting my mouse necessarily, but like I can usually see it doing stuff depending on what the task is. But here will it always be hidden like you're never I can be using my computer like normal and I don't even know that it's doing these things. It's always
56:55kind of in a separate place or where's the where's the boundary between?
57:00Yeah, we the browser is we package the browser ourselves so it doesn't interfere with the browser that you use. We don't you know all the cookies on the browser that you use stay on the browser that you use, right? Our browser is a fresh sess session.
57:13Can I have it? What if I want it to be in my normal browser? Can I say hey like put a couple of these things in my cart and show it to me so I can review them?
57:24that is coming soon.
57:25Okay. Okay. So, right now it it has its own sort of app space with its own sessions and everything. Oh, but if I wanted to log into stuff, that's where I would give it my passwords and Exactly. So, you could give it your Amazon login and then it will add it to your So, I could then it could add it to the cart and then I would see it because the cart is synchronized across the browser windows. Okay.
57:45I think we should order something for your kids.
57:48Okay. So, what do I I need to put something in my vault here. Yep.
57:54I'll add a new login.
58:00All right. We'll give it a try.
58:04No, I It should work. It should work with that.
58:06That works now. Okay. Okay. Subdomains.
58:10Okay. Do I need to tell it to log in or will it figure that out?
58:14You know, I think the cart works without logging in. So, if you want it to be in your loggedin cart, you would on Amazon, you can add things to cart without logging in.
58:21I know. But will that will that span across your browser?
58:25So if you want it to be in your logged in cart, you probably should tell it to Okay.
58:32So tell me some of the things that you guys have done with this that have saved you time. What what are other use cases while it's uh sitting here churning?
58:39Well, one thing I'll say while while it's doing this, which I which I love, is um latch is not exposing the password to the agent to the to the cloud agent.
58:48So, Latch inserts the password directly into the into our browser that we ship with Latch. So, that's all part of our privacy model where we do everything we can to keep as much on your machine as possible. Tom, at the end of the day, like you're an important guy. You don't you don't want all of your stuff being shipped to all of these cloud services.
59:09I agree. I am sensitive with my passwords and my privacy, etc., etc. So I again the paranoia I always think about attack vectors etc etc. So yeah that's I like knowing that that you're going to you're not sending passwords to random external cloud models. Yeah, it's we it's all sort of the the least privilege meth model where we we want to allow you
59:37to do the thing that you want to do but with the with the with the least the least possible privilege that we need to we need to expose in order in order for that to be able to get done.
59:47Yeah. Why don't we go to the audit tab and we can see what it's uh so what does scope blocked mean? Oh, it denied. So, you can actually see why it if you click on that.
1:00:07Oh, that means the model didn't return in time.
1:00:10Yeah. At one time I had an assistant and I would text her over iMessage and it was amazing. And she had access to my emails and my login. And I no longer have that assistant. I use this for everything that I would use her for. So, if I get a bill in the mail, I'll take a photo of that bill and ask Latch to pay it. Um, I love using it for like long
1:00:39email threads. I I signed up to coach my s kids soccer team. There was 18 emails. I don't have time to read all of that.
1:00:46So, Latch went through all of those emails, figured out the time that is best for everybody else that's free on my calendar, replied to the email, put it on my calendar. I run it every day to figure out what are the most important uh urgent and important things that I'm not attending to. And um you know, I told me that for I have a rental property, the mortgage wasn't getting paid for the rental property.
1:01:11Uh so, I had it log in and pay that mortgage. Yeah, that's important.
1:01:15Um, so really just managing honestly managing my email inbox and dealing with this like low-grade noise that slows us all down or at least all of us normal people who don't have assistants um has been has been a big use case. Oh, this is a big one. My wife and I are terrible at coordinating schedules. She'll commit to things with the kids. We've got three kids. I'll commit to things for our family. We we don't tell each other. For some reason, using Google Calendar has
1:01:44just been a struggle for us. Um, now whenever we commit to something, we just text the phone number and it gets put on our Google calendar and we'll get alerted if we have a conflict.
1:01:54Okay, cool. So, so really like uh things you would have an regular assistant do. Plow is designed to do that, but has the really easy installation to make it super easy to get into.
1:02:05You're not having to figure out how to create new phone numbers or WhatsApps or channels on whatever Slack or whatever. It's just like text this number. It's taken care of and there's this auditing and rules and so it's just smoothing out the whole thing for a more consumer grade experience. Let's see. I want the Stitch toy and the fierce dinosaur.
1:02:33I used it the other day. I was on the go and I remembered, oh, I had booked a reservation for a hotel and I needed to cancel it before the the cancellation policy expired. So, in the old world, I would just forget about that. I'm on the go and I would end up having to pay for that hotel, right? And in the new world, I just text Plow Latch, can you can you cancel that reservation?
1:02:58Um, so stuff like that where you're dealing with support teams or you're you're going through like, you know, these kind of arcane flows in order to pay a bill or or cancel something or change an order. Those all um, you know, they'll take me 15 minutes to figure out where's the cancellation button on this thing. This they're intentionally hiding it. I know it's here somewhere, right? And and Plow Latch can take care of it.
1:03:23Okay. So you could have it do the do the like 12step cancellation process for New York Times or whatever.
1:03:30Yeah, exactly. Amazon overcharged me for something. It's a kind of a long story even to talk about it here. It's just like the how I got to a point where I was paying $50 more than I should have is, you know, I just like logged into the Amazon support and chatted with some dude named Eric to to get me my $50 back. And normally I just would pay the 50 bucks.
1:03:50Looks like I ran out of money. WW want.
1:03:54Oh, interesting. So, let's fix this real quick. If you open up the web and you go to api.plow.co/app. Yeah, we give everybody 10 bucks, but my guess is this was already used when you were testing the old product. So, if you hit 500 and hit pay with stripe and then hit under promo code on the left team 501 apply.
1:04:39Okay. So, now I can What should I tell it? Try again.
1:04:44I'll just say try again or something.
1:04:48How do you get it to integrate with your email? Say like how do you have it scan your email? Is it is it just driving that via your browser and doing this normally do searching for stuff and whatever? It's not like indexing have keeping its own index or any of that.
1:05:04The old version of plow had a Google connector a you know a Google developer account and everything. We are migrating that over. And the way that and this is this is also I think this was just merged into main. The way that the way that it works now is we use the CLI the Google CLI on your machine. So um you know your agent will tell latch to run the CLI command to fetch your
1:05:33Google email or composite email or whatever and all of that goes through the adversarial reviewer and all of that is on your machine. Your machine then you know communicates with Google directly. um and then returns the returns the data back to the agent through latch. I did hear a user was using like they had put in their Google credential in the vault and like like they were just using gmail.com the browser to like read their email.
1:06:01All right, moment of truth. There's the Stitch and the Fierce Dinosaur.
1:06:07Those are some cool Legos.
1:06:09[laughter] Yeah, good choices. Plow.
1:06:12Okay, you can have it check out and then if you have you if you have buyers remorse, you can have it cancel the order. [laughter] Actually, these probably would be these are great. Okay, so when um like what's your timeline here? When do when is this ready for for prime time? Like you guys are already kind of testing it yourselves and we're testing internally. We want to we want to do a limited release in a week.
1:06:40I'd say launching with the community about a month out. But Tom, it's going to be magical because you'll you'll just be able to text the phone number. The agent will get spun spun up. You can start talking to it. You can then download Latch, right? And now I'm going to pitch you as if you you're an investor. Um, so the the really what I what I see is when I start using latch or when I use plow with other people, they get it, you know, like if I'm going on a trip with people, you know, like I
1:07:09can use it to book the reservation and they're like, "Wow, this is amazing. I want it, right?" Or like if I'm getting dinner, getting takeout or something, I just put Plow on, Plow orders the takeout, you know? And so that moment where they want it is the moment where Plow can actually side text them and be like, "Hey, you know, if you want this, just let me know. I can I'll set it up for you right away."
1:07:31Yeah. Yeah. Yeah. I I would love that for ordering GrubHub, you know, like it's such a manual task to be like, I'm going to order exactly the same things as before. Maybe I want a slight tweak and it's like five minutes, you know, this is not rocket science kind of stuff.
1:07:47Okay. So, so if it So, if it deems that I'm about to spend money, it'll looks like it'll like do an extra confirmation, I guess. I guess so. [laughter] Yeah. Confirming like the credit card to use and all that.
1:07:59Cool. So, this is Yeah, this is nice. So, this will I'm out and about. I'm texting this number. It's doing stuff, but it's doing it with my So, my computer needs to be on.
1:08:12If you're going to use the computer computer use functionality, right?
1:08:15Okay. But but I could have it do other things that don't require my computer that it could do because it's a cloud agent.
1:08:22Wow, look at that.
1:08:26It's maybe a little chatty in the things [laughter] that it's two buttons labeled the same thing, Tom. I don't know if you wanted to know that, but like I'm pretty sure this is critical information for [laughter] you.
1:08:39Sweet. Got Legos coming tomorrow.
1:08:44So our goal, Tom, is to get this to a place where you are comfortable installing this on your main machine. That will be when I know we're like we're ready to launch. So yeah, that's that's cool. I like this a lot. This is this is rad.
1:08:59If we open source the client, would that make you more comfortable installing it on the machine where you've got all your personal data and all your I mean marginally, I suppose.
1:09:11I don't know that that's critical. I think it's really just a matter of building trust with the system itself, you know, and and we we're starting to get into a world where these LLMs are sophisticated enough that clearly Claude with Cloud Code is like, I don't know, like people don't like saying yes all the time to stuff, you know, individually to all these commands. So, auto mode is default because they feel like it's safe. They safe enough. And I think that that's a that's a thing in the world that is happening where people
1:09:40are just getting more comfortable with these. And as long as you have decent policies and kind of things in place where you're going to have an LLM that's checking for you and you build up that trust over time, like you leave it in in the um what was it in the where where were the modes here? If you leave it in the under rules. Oh, that's in rules. Yeah, if you if like ask me every time and you know, it's always suggesting the stuff
1:10:10that you would agree with, then over time you start to be comfortable with it. So, it's just a this, you know, you build up trust with a product over time, but having it ask me is a nice way to to be able to try it out without feeling like you're putting yourself at undue risk, which I think is nice.
1:10:28Cool. Any any feature requests? I mean the one the one that as I'm building trust with this I think it would be cool to have a bigger way to see or I guess an immediate one is like I want to see whatever that little browser I guess it closes when it's done but I'd like to be able to see what it's doing more directly just to as a trust building experience of like just I don't know let me watch what you're doing like a you have some new intern that comes along and you're like do this thing and I'm going to kind of observe just to
1:10:57make sure that you're being a reasonable new person at this task. So, being being able to observe it in that way, like this is really nice having this audit log and knowing what it's doing and what it was what it allowed and denied. I can come in here and I can be like, well, what was, you know, what was that about?
1:11:14Like that. I like that. I like this concept of rules. I kind of want to, you know, as I get more sophisticated, I'd want maybe something a lot more capable than just a single text box. Maybe I want I don't know how, you know, but I want to be able to invite other people to do certain things or whatever.
1:11:33And and so making that more competent, understanding what people are trying to do and how complicated they want to get, make it really easy for easy cases, but then allow for growing complexity to to to adjust to different scenarios or to teach it. I guess I wonder if it doesn't if it's not doing something the way that I want it to do it, can I teach it? Can I tell it like, oh, next time when I'm ordering pizzas, you know, don't forget to add the garlic dipping sauce or
1:12:03whatever and then it just knows like can it build it? Is there a memory feature where it's maybe building up that that kind of knowledge over time? I guess that's that's a specific question.
1:12:13What's your what's your take on memory?
1:12:16There's two different kinds of teaching.
1:12:18So one is teaching the adversarial reviewer and this is coming where if it denies something you'll be able to to it'll it'll suggest edits to the language in order for you to guide it around like hey actually this is okay to run. Um, so there's that teaching and then there's teaching your personal agent and there there's a ton of prior art around you know what kind of memory should you use and actually this is maybe the last thing I want to show you because for example openclaw has its own
1:12:46memory infrastructure and so if you hit agents and let's say you want to use openclaw because you like how they do memory you know and you like how you may already have an openclaw container that's tuned to your preferences because you've been using it for a while um and so you can give OpenClaw access to your to to your Mac. Um, if you just hit agents, the agents tab, connect MCP client, and I won't have you do this because it exposes a credential
1:13:16that anyone watching the podcast could use to access your Mac, but if you hit um get a static credential, then that will that that creates a bearer token that you can pass to any agent and give it access to the MCP server that you're running.
1:13:30Gotcha. Okay. So really so it is agent agnostic. You can really plug in whatever here.
1:13:35Plow is really plow latch I guess specifically is about being the bridge to your computer and being the adversarial agent and the rules engine for how that's going to work and how that's going to be safe.
1:13:50Yep. And we have like a you know bring your own agent. For many users, they're going to want to just quickly try it, you know, and so we have kind of a a starter container that you can easily spin up like you did here. But yeah, for others, they they're they already have their own agent infrastructure.
1:14:06Okay, cool. I love it. Yeah, this I mean, this feels really good. I I always think about usability and UX for these products and and this is this is very nice. It's easy to get started. Instantly, I was doing useful things. That's a big deal.
1:14:22Cool. All right. Well, continue spending your money then. [laughter] Thank you for the investment.
1:14:28You're welcome. No, I'm super excited with where you're taking this. Like, you know, we invested PWV invested for a reason and it's because of this vision that you're playing out here. I think it's great.
1:14:40Thanks, Tom. That was fun. Sweet.
1:14:42Thank you, Sam Plucas. Always a pleasure. Yeah. Thanks, man. [music]