dr.chaos

Who Should Run Your Digital Life? Muse, Amazon Quick, Hermes Agent and OpenClaw Compared

Aamir Lakhani15 min read

Field guide to AI agents. Research snapshot: September 30, 2026. Researched from product repositories, official announcements and contemporary coverage.

These four products are often discussed as if they were interchangeable "AI assistants." They are not. Muse is a polished consumer service. Amazon Quick is an enterprise workbench. Hermes Agent is a self-improving open-source runtime. OpenClaw is a local-first gateway that lives in the chat apps you already use.

My read

For most people, the real choice is not "which model is smartest?" It is "who operates the infrastructure, where does my data live, and how much setup am I willing to own?"

The short version: choose convenience, workplace governance, self-improvement, or local-first control. You cannot maximize all four at once.

AssistantBest for
MuseLow-friction everyday errands.
Amazon QuickGoverned work across company data.
Hermes AgentTinkerers who want an agent that learns.
OpenClawLocal control and chat-first access.

NOTE

First, a naming correction: "AWS Quick" really does exist. Amazon Quick is the current workplace-agent product. Amazon Q Business is now the legacy path; the separate Amazon Q Developer line is being retired in favor of Kiro (AWS).

01 · Muse: Meta's hosted personal agent

Muse is the easiest of the four to picture as a concierge: ask it to research, shop, book, fill forms or handle email, and it can keep working after you close the app.

Muse mobile interface booking two movie tickets and selecting seats in a browser
Muse's consumer pitch is simple: conversation turns into action. Image via Android Headlines.
PriceWhere it runsModel choice
Free; reported $20 Power and $100 Maximum tiersiOS, Android, web, WhatsApp and MacMuse Spark family only

What is under the hood?

Each session runs inside a cloud-hosted Secure VM with its own browser. A separate Sentinel layer governs permissions and reviews internet-bound actions. Sensitive steps such as spending money or sending a message require approval, and users get an audit trail. Meta has also described a planned "Confidential VM" option with user-held encryption keys (Meta).

That architecture is more serious than a chatbot with a browser tab. It separates the agent doing the work from the layer deciding whether the work should be allowed.

Where it shines

The product is packaged for normal life. Commerce and productivity connections include Gmail, Spotify, Stripe Link, OpenTable and a growing small-business connector set. Developers reportedly submitted well over 1,500 connector applications within days of the framework opening (Dimsum Daily, Unite.AI).

What I like

  • Real end-to-end task execution
  • Very little setup for the user
  • Secure VM, Sentinel and approvals
  • Strong commerce momentum

What gives me pause

  • Closed service and one model family
  • Chats reportedly train Meta models by default unless disabled
  • US rollout, 18+, with Canada also cited in later coverage
  • A reported Marketplace address-disclosure incident

WARNING

Verification note. The architecture comes from Meta's own launch announcement. Pricing, weekly token limits and the card-at-signup requirement come from TechCrunch's reporting, and the training default from Morning Overview. Treat the free/$20/$100 figures as a snapshot, not a buying guarantee.

02 · Amazon Quick: AWS's governed workplace assistant

Quick is not trying to book your dinner. It is trying to understand your company's documents, produce research, build dashboards and automate repeatable work without trampling permissions.

Amazon Quick desktop interface preparing a user for a meeting by reading files, messages, Slack and Outlook
Amazon Quick's desktop experience pulls context from connected workplace systems. Official Amazon image from About Amazon.
PriceBusiness feesCore stack
Free / Plus $20 ($25 billed monthly) / Professional $20 / Enterprise $40 / Max $100 per user monthly$250 per account monthly on Professional and Enterprise; Enterprise agent-hour overage at $3Chat, Research, Sight, Flows and Automate

What is under the hood?

Quick runs in AWS. Quick Index retrieves company information while respecting source permissions; Quick Research combines internal and web sources; Quick Sight handles BI; Quick Flows and Quick Automate turn tasks into workflows. Models are served through AWS and Bedrock, while administrators control identity, web search and connected data.

The most important distinction is organizational memory rather than personal memory. Quick indexes what a worker is allowed to see, then wraps it in enterprise controls, SSO, shared spaces and audit trails. AWS states that customer prompts and data are not used to train foundation models (YourStory).

Why the name is confusing

Quick grew from QuickSight into Quick Suite in October 2025, then became Amazon Quick. Amazon Q Business closed to new customers from July 31, 2026, with AWS pointing buyers toward Quick (AWS). Amazon Q Developer is a separate coding product: new sign-ups ended May 15, 2026 and support ends April 30, 2027, with Kiro positioned as the successor (AWS, Atlan).

What I like

  • Research, BI and automation in one suite
  • Permission-aware enterprise retrieval
  • 1,000+ integrations via MCP and OpenAPI
  • Cloud agents continue while devices are off

What gives me pause

  • AWS identity and billing lock-in
  • Infrastructure fee and agent-hour overages
  • Product-name and migration churn
  • Much less useful for personal errands

TIP

Pricing. Tiers and fees above are from AWS's official Quick pricing page as of September 30, 2026. The Professional tier cannot buy agent-hour overages; confirm current terms and a quote with AWS before you commit.

03 · Hermes Agent: Nous Research's self-improving open-source runtime

Hermes is for people who do not merely want to use an agent; they want to shape one. Its standout idea is a learning loop that turns successful work into reusable skills.

Hermes Agent terminal interface showing available tools and skills
The terminal-first Hermes experience exposes tools, skills and the active model. Screenshot from the Ollama integration guide.
Software costYou pay forModel choice
Free, MIT licensedYour model inference and hostingAny OpenAI-compatible endpoint

The differentiator: compounding skills

Hermes can reflect after a complex task, write a reusable skill, and later refine underperforming skills. Its memory combines curated user files with FTS5 session search and LLM summaries. In plain English: it is designed to get better at your way of working, not only remember what you said (Hermes Agent repository, TechTimes).

The rest of the stack is unusually broad: 40+ tools, MCP servers, sandboxed Python execution, subagents, checkpoints, scheduled jobs, vision, voice, browser automation, messaging gateways and execution backends ranging from a laptop to Docker, SSH, Modal, Daytona and Vercel Sandbox. It can also expose an OpenAI-compatible API server.

Freedom has an operations bill

The software is free and runs with many providers, or local models, but someone still needs to configure keys, hosting, sandboxes, updates and backups. Agent quality moves with the model. Community testing cited in the research suggests small 8B-class models can struggle; treat roughly 8–12B as a practical floor, not a hard compatibility rule.

What I like

  • A genuinely distinctive skill-learning loop
  • Model-agnostic and portable
  • MIT licensed with a huge community
  • Runs from a cheap VPS to a GPU cluster

What gives me pause

  • You own hosting and maintenance
  • No conventional vendor SLA
  • Security isolation must be configured
  • Results depend heavily on model choice

NOTE

Worth noting: NVIDIA lists Hermes among roughly ten agent harnesses that officially support Nemotron 3 Ultra (OpenClaw is another). That is a signal of technical credibility, but not the same thing as managed enterprise support (NVIDIA).

04 · OpenClaw: a local-first gateway for an assistant everywhere

OpenClaw's central idea is not a better chat window. It is one gateway on your own hardware, connected to every chat app and model provider you care about.

Third-party OpenClaw Easy dashboard showing assistant status, channels, permissions and configuration
A third-party OpenClaw Easy dashboard illustrates the gateway model; it is not the core project's official UI. Image from OpenClaw Easy; an account email visible in the original has been blurred.
Software costData locationReach
Free, MIT licensedYour hardware, under ~/.openclaw20+ chat channels, native apps, UI, CLI and TUI

A gateway, not a single model

The TypeScript/Node gateway is the local control plane for sessions, tools, events and channels. Models are plugins: Claude, Codex, other hosted providers or fully local models can be swapped without rebuilding the rest of the setup. State, memory and credentials stay on the host; the official repository says OpenAI is a donor, not an owner (OpenClaw repository).

Its breadth is the appeal: WhatsApp, Telegram, Discord, Slack, Signal, iMessage, Teams, Matrix, Google Chat and more can all reach one assistant. Add persistent memory, proactive messages, browser and shell tools, scheduled tasks, MCP, multi-agent routing and a large community skill catalog.

Local-first does not mean risk-free

OpenClaw's own security model treats inbound messages as untrusted. That is the right framing: a chat message can become input to an agent with browser, file or shell access. Loopback binding, plugin allowlists, pairing approval, audit logs and sandboxing help, but the operator has to use them. The main session's tools may otherwise run on the host.

Loopback binding is also not a wall. CVE-2026-25253 (CVSS 8.8), fixed in release 2026.1.29, allowed one-click remote code execution through a malicious link even against a gateway bound to localhost, because the victim's own browser makes the connection (The Hacker News). Patching is part of the operator's job.

What I like

  • Best chat-channel coverage here
  • Full local control of state and memory
  • Swappable hosted or local models
  • Foundation governance, no subscription

What gives me pause

  • Installation, updates and hardening are yours
  • Messaging creates a real injection surface
  • No vendor support SLA
  • Quality varies with provider and setup
  • The community skill registry has already been hit by a malware campaign, and the gateway has had a one-click RCE (see the security lens below)

NOTE

Numbers move fast. The official repository showed roughly 391,000 stars and 82,000 forks when fetched on September 30, 2026. Those counts are a dated snapshot, not a permanent product metric.

The useful comparison

Ignore the shared "agent" label. The meaningful differences are ownership, memory, model choice and who is on call when something breaks.

Two-by-two map. Horizontal axis: the vendor operates it versus you operate it. Vertical axis: personal life versus work. Amazon Quick sits in vendor-operated work, Muse in vendor-operated personal, Hermes Agent in self-operated builder territory, and OpenClaw in self-operated personal.
Figure 1. Where each assistant sits. Moving right buys control and costs operations; moving up buys governance and costs personal usefulness.
DimensionMuseAmazon QuickHermesOpenClaw
Operating modelMeta-hosted cloudAWS-hosted SaaSSelf-hosted runtimeSelf-hosted gateway
PriceFree / $20 / $100 reportedFree to $100/user + account feesFree software + inferenceFree software + inference
Model flexibilityMuse Spark onlyAWS-managedOpenAI-compatible providers50+ providers and local models
MemoryPersonal context + forget controlPermission-aware company indexSelf-created skills + curated memoryPersistent local memory + outreach
Best interfacePhone, web, WhatsAppWork desktop and webTerminal, web, messagingYour existing chat apps
Privacy postureCloud; reported training default is opt-outCloud; AWS says no foundation-model trainingLocal state; chosen provider sees promptsLocal state; chosen providers/channels see traffic
Ops burdenLowLow for users; admin setupHighHigh
Comparison grid of Muse, Amazon Quick, Hermes and OpenClaw across who runs it, price, models, memory, interface, where data stays, and operations burden.
Figure 2. The comparison table above as a single picture, for sharing.

Muse and Quick ask you to trust a vendor. Hermes and OpenClaw ask you to trust yourself as an operator.

The security lens: all four have the lethal trifecta

In the companion piece, How Attackers Attack AI, I argue that an agent becomes dangerous when it combines private data, exposure to untrusted content, and a way to act or communicate. Every assistant in this guide has all three. That is not a flaw in any of them; it is the product. What differs is where the brakes are, and who maintains them.

Private data it touchesUntrusted content it readsWays outWhere the brakes are
MuseEmail, accounts and payment methods you connectWeb pages, listings and email it reads during errandsPurchases, messages, form submissionsMeta's Sentinel layer and approvals; you cannot inspect or tune them
Amazon QuickCompany documents, chats and BI data within your permissionsInternal documents anyone can edit, web research resultsFlows and Automate actions, connectorsAdmin controls, SSO, permission-aware index, audit trails, owned by your admins
HermesYour files, keys, memory and whatever tools you enableWeb, files, messaging gateways, tool outputShell, browser, code execution, messagingWhatever sandbox and backend you configure, plus the skills it writes itself
OpenClawLocal state, credentials and memory on the hostEvery inbound chat message, community skillsShell and browser on the host, proactive messages to your contactsLoopback binding, allowlists, pairing approval, sandboxing, if you turn them on
Heat-map style grid: for each of the four assistants, the private data it touches, the untrusted input it reads, its ways out, and who owns the brakes, colored by exposure.
Figure 3. Every assistant here has all three trifecta ingredients. The real difference is who owns the brakes.

What that means for each:

  • Muse has the right shape, but it is a black box. Separating the worker (Secure VM) from the decider (Sentinel) is the containment pattern I recommend for any agent. The catch is that you cannot audit Sentinel's policy, and an approval prompt is only as good as its description of the action. Read what you approve.
  • Amazon Quick lives in EchoLeak's product category. A permission-aware assistant that reads company mail and documents and answers questions is the same shape as Microsoft 365 Copilot, which EchoLeak turned into a zero-click exfiltration path. Permission-aware retrieval stops Quick from showing you what you cannot see. It does not stop a document you can see from carrying instructions. If you are evaluating Quick, ask AWS how it handles instructions embedded in indexed content, and whether any output can trigger an automatic fetch such as images or link previews.
  • Hermes's best feature is its sharpest edge. An agent that writes its own skills can turn a one-time injection into a standing instruction: the memory-poisoning pattern from SpAIware and AgentPoison, except the agent does the persisting for the attacker. Keep generated skills in version control, review them like code, and do not let a session that read untrusted content create or edit a skill without review.
  • OpenClaw's skill catalog is the ClawHavoc supply chain. ClawHub, OpenClaw's community skill marketplace, was hit by the ClawHavoc campaign in January and February 2026. Koi Security found 341 malicious skills, 335 of them delivering the AMOS stealer through one command-and-control server; Antiy CERT later counted 1,184 across 12 author IDs (Antiy CERT). Local-first protects your data from a vendor. It does not protect you from a skill you installed yourself.

If you self-host Hermes or OpenClaw: a hardening checklist

  1. Keep the gateway off the internet, and patched. Bind to loopback and reach it over a VPN or tailnet, never through a public port. Loopback alone did not stop CVE-2026-25253, so stay current.
  2. Give the agent its own box. A separate OS user, container or VM, with no access to your personal SSH keys, browser profile or cloud credentials.
  3. Allowlist who can command it. Only your own accounts, per channel. Treat group chats and forwarded messages as hostile input.
  4. Require approval for consequences. Sending, paying, running code and writing to long-term memory should all need a fresh yes.
  5. Pin and read skills. No auto-updates from registries; read the skill and anything it fetches; prefer publishers you can identify.
  6. Kill silent egress. Disable automatic image loading and link unfurling in agent output, the channel EchoLeak and CamoLeak used.
  7. Use scoped, capped model keys. A dedicated API key per agent with a spending limit, so a hijacked loop cannot run up an unbounded bill.
  8. Version memory and skills. Back them up, and diff them weekly; an unexpected new instruction is your earliest indicator of compromise.
  9. Log tool calls. Keep a record of which message caused which tool call, and alert on new outbound domains.

So, which one should you choose?

Pick Muse if…

You are in a supported market, want errands handled with minimal setup, and accept Meta's cloud and data defaults in exchange for convenience.

Pick Amazon Quick if…

You are buying for a company, especially an AWS shop, and governance, BI, internal research and workflow automation matter more than personal-life tasks.

Pick Hermes if…

You are a developer or researcher who wants a portable agent that can learn reusable skills, and you are comfortable owning the stack.

Pick OpenClaw if…

You want one always-on assistant across your existing chat apps, local control matters, and light systems administration does not scare you.

My read

Final recommendation. Start with the operating model you can live with. Capabilities will converge. Data control, vendor dependence and maintenance responsibility will not.

Sources and open questions

Research was completed September 30, 2026. Product details move quickly; figures below reflect what the cited pages reported or displayed on that date.

  1. Meta: Introducing Muse: official announcement, Secure VM, Sentinel, approvals and Confidential VM plans.
  2. TechCrunch: everything new coming to Muse: pricing tiers, token limits and card requirement.
  3. AWS: Amazon Quick pricing: official tiers, account fee and overages.
  4. AWS: Amazon Q Business availability change: closed to new customers.
  5. NVIDIA: Nemotron 3 Ultra for long-running agents: supported agent harnesses, including Hermes and OpenClaw.
  6. Antiy CERT: ClawHavoc analysis and The Hacker News: CVE-2026-25253: OpenClaw ecosystem security.
  7. Nous Research / Hermes Agent repository: official repository, MIT license, architecture and feature set.
  8. OpenClaw repository: official repository, MIT license, foundation, privacy defaults, channels and architecture.
  9. AWS: Amazon Q Developer end-of-support announcement: official dates and Kiro migration.
  10. Morning Overview: Muse privacy defaults: secondary reporting on training, Sentinel and the Marketplace incident.
  11. Tech Insider: Muse launch guide: reported prices, token limits, US rollout and card requirement.
  12. Orca Router: Muse Agent: reported bug bounty and Confidential VM.
  13. Dimsum Daily: Muse retail integrations.
  14. Unite.AI: Muse small-business connectors.
  15. Layer 3 Labs: Muse architecture explainer.
  16. About Amazon: seller-assistant plugin for Amazon Quick: official product framing and seller promotion.
  17. Cloudvisor: What is Amazon Quick?: contemporary pricing and capability overview.
  18. Omega Technology Solutions: Quick mobile Activity Feed.
  19. YourStory: Amazon Quick Suite: launch, regions, pricing and data-training statement.
  20. Atlan: AWS agent product changes: naming history and Q Business status.
  21. TechTimes: agent business models: Hermes learning loop and open-source business models.
  22. Awesome OpenClaw: community skill and integration catalog.

NOTE

Still open. Nous Portal's subscription price was not found, and conflicting Hermes version numbers were left out. AWS's "no training on Quick data" statement and Muse's Canada expansion were confirmed only through secondary coverage. Muse adoption numbers were third-party estimates, so they are not used as proof of active users.

Aamir Lakhani

Founder · Dr. Chaos

Aamir Lakhani is a leading senior security strategist responsible for providing IT security solutions to major enterprises and government organizations. He creates technical security strategies and leads security implementation projects for…

~/related

Keep digging

More research along the same attack path.

How Attackers Attack AI

The serious attack surface is no longer the chatbot. It is the agent's toolbelt: retrieval, memory, skills, CI pipelines, credentials, and every renderer or proxy trusted to move data. A field analysis of EchoLeak, malicious agent skills, coding-agent compromise, state-scale campaigns, and data poisoning, separating confirmed incidents from research demonstrations, with the containment architecture that actually holds up.

Aamir Lakhani19 min read

Kimi K3 and K3 Swarm: An Open-Weight Model Review from the Red Team Chair

A balanced cybersecurity review of Moonshot's Kimi K3 and the multi-agent K3 Swarm. Not "is it smart" but the question a red team actually asks: does an open, self-hostable, agentic model make you more effective on an engagement, and what does it give you that Claude and GPT cannot? Data that stays in the room, no vendor holding your engagement hostage, cost at scale, and a swarm that fits the work, weighed honestly against where the closed frontier models still win.

Aamir Lakhani13 min read