Commentary#Multi-agent#Coding agent#AI safety

Send prompts, not code: Peter Steinberger's agent workflow

OpenClaw creator Peter Steinberger explains his agent workflow on AI Worth Using: fresh-context review agents, local databases over cloud MCP, prompts over PRs.

Two round review bots face each other across a git branch: one inspects code with a magnifying glass, the other holds up a prompt bubble, with OpenClaw's red lobster mascot in the corner (cover generated by the editors)

Peter Steinberger once connected an agent with full access to his computer to a public Discord server: anyone could command it, and that night strangers tried to break into his machine. Steinberger — creator of OpenClaw, founder of PSPDFKit, now an OpenAI employee — is the guest on episode 3 of the AI Worth Using podcast, hosted by former Dropbox executive Sam Odio and GitHub co-founder Tom Preston-Werner. The episode’s Apple Podcasts title says it plainly: “stop sending me code, send me your prompt.”

When agents can produce hundreds of changes a day, where does the engineer’s job move? Steinberger’s answer has three layers: hand review to a fresh-context agent, hand testing to a real sandbox, and move the signal in outside contributions from code to prompts. Preston-Werner, who keeps his agent locked inside a Docker container, marks the cautious edge of the same map. We distilled the actionable parts of the conversation and checked the claims against the repo and public records — a widely shared Chinese write-up casts Tom as the interviewee and claims “hand-writing code is now manual labor”; both drift from the actual episode, as our fact-check table below shows.

Key points

  • The main OpenClaw repo currently has 3,354 open pull requests (measured via the GitHub API on 2026-10-08). In the interview, Steinberger argues that for bug fixes, an issue with the full reasoning trail beats code an agent can regenerate anyway.
  • His auto-review loop: after the main agent finishes code, it spins up a brand-new instance with a blank context whose only job is finding fault. The two debate for up to 10 rounds; one strict pass takes about two hours, and he does a human acceptance pass only after every 5–10 merged changes.
  • On security, his conclusion: OpenClaw and commercial coding agents share the same sandbox primitives, and the only difference is default permissions. Absolute safety doesn’t exist; Docker or a cloud server are both reasonable places to put an agent.

The review loop for agent code

The reviewer in Steinberger’s setup is another instance of the same model with no memory of writing the code. The main agent summons it with one instruction — “review everything I just changed” — and the instance attacks the diff the way a well-rested colleague would, with none of the author’s sunk cost. He frames this as building the agent’s confidence in its own code.

The debate that follows is the point. The reviewer returns findings; the main agent, holding more business context, defends its choices or concedes it missed an edge case, fixes, resubmits, and the probabilistic new instance may catch yet another defect. Sometimes they converge; sometimes the main agent adds a comment explaining that a design was intentional. This tug-of-war can run a full ten rounds. It is slow — but by the end of the ping-pong match, he says, the logic holds up.

Logic holding up and the program actually running are different problems. His second building block is the test sandbox (he built an open-source version called Crapbox): the agent compiles and installs its work in a throwaway VM, and for GUI apps it drives the interface itself — screenshots, simulated clicks, end-to-end verification. He insists testing happen off your main machine, because a host full of odd dependencies hides exactly the failures that matter.

The cost is time: a PR he could have filed by hand in ten minutes takes the loop two hours. What he buys is two hours away from the screen and the ability to run twenty tasks in parallel. His own role sits at the end: after every 5–10 merged changes he does an acceptance pass, harvests the blind spots the agents missed, and tunes the prompts. The human moves from line-by-line reviewer to taste-keeper and prompt-tuner.

From pull request to prompt request

The episode’s most quoted claim lives here: for bug-fix contributions, a clear issue with precise reproduction steps is worth more than a patch. His reason is practical — reviewing an external PR, or rewriting it, often costs the maintainer more time than rerunning the reasoning locally would.

OpenClaw’s repo operationalizes this: when an outside contributor prepares a PR, their agent will (usually — it’s probabilistic) offer to attach a sanitized prompt log, with a background thread stripping private and irrelevant details. What he reads in that log is the signal gap between “fix it” plus a screenshot and a contributor who pushed back and forth on how the change fits the architecture. He doesn’t care about prompt wording; he cares whether the person understood the problem and took responsibility for the fix.

The practice hasn’t caught up with the position. As of 2026-10-08, openclaw/openclaw has 3,354 open PRs (GitHub API), so “send prompts, not code” remains one maintainer’s plea rather than a community default. He also keeps one exception: brand-new features he wants to shape by hand, iteratively, because working with the thing sparks the next idea. Prompts replace bug-fix contributions, not design.

Security is now a checkbox

Roughly a third of the episode is a security debate, triggered by Preston-Werner’s admission that he containers OpenClaw because he doesn’t dare give an agent his email. Steinberger’s reply has two steps.

First, the primitives are identical. Commercial closed tools and open systems use the same sandbox mechanisms; the only difference is defaults. OpenClaw ships with read access to everything and can be tightened to a single workspace; commercial tools ship with everything off and nearly useless until you opt in, piece by piece. He has spent the last few months hardening the same architecture to enterprise grade for internal use at OpenAI — engineering as trade-offs, all the way down.

Second, absolute safety is the wrong target. He cites a recent disclosure (we could not locate the original write-up, so treat this as his account): an attacker posing as a Cloudflare anti-bot check talked a Claude Code agent into opening a series of links encoding the English alphabet, spelling out the system username one letter at a time. The crude “ignore previous instructions” attacks fail against current models, yet a clever enough chain still finds a seam — and the total loss in that case was a username. Someone ran the experiment in reverse, posting an OpenClaw with their email attached and daring the internet; 6,000+ attack emails arrived and none succeeded. Both stories are his account, not ours. NVIDIA has staffed a team that triages OpenClaw vulnerability reports daily (NVIDIA’s partnership we verified in our earlier OpenClaw Enterprise report; the daily triage detail is from the interview). His honest boundary: unless a nation-state actor is after you specifically, current defenses hold.

Preston-Werner plays the counterweight throughout, and his closing position is worth recording: convinced by this risk assessment, he plans to connect the agent to more of his personal services. Trust accumulates through accident-free use, the way driving does. The real gap between the two camps is far smaller than the Chinese headline suggests.

Local databases beat cloud MCP

The most immediately useful stretch of the conversation is about how agents reach data. Steinberger’s claim: models are fastest skimming plain text and SQLite files on disk. A cloud MCP connector round-trip costs about two seconds per search and 10–20 seconds to assemble scattered fragments; point the same agent at a local database and the full scan takes 0.2 seconds.

Hence his CLI crawler ecosystem: slacrawl for Slack, discrawl for Discord, plus WhatsApp and iMessage tools. The trick is mundane — if you’re signed into the Slack desktop app on that machine, your messages already sit in a synced local SQLite cache, and the agent can read it. The vendor can gate its API all it wants; it can’t stop you from reading your own machine’s cache.

For readers outside the OpenClaw orbit this generalizes: when wiring data into an agent, flatten the local path first (CLI tools, cached databases) and reserve cloud connectors for services with no local footprint. The difference between seconds and sub-seconds decides whether the agent feels like a search box you stare at or a colleague who answers.

A digital company per person

Steinberger’s eighteen-month horizon is organizational. In the architecture he describes, the main agent stops spawning disposable sub-agents and instead creates persistent ones that own a domain: ask to get fit and it hires a health coach that pings you; ask to build a product and it spins up a maintainer that keeps the full development context and wakes up each day to check GitHub. The user deals only with the meta-orchestrator; delegation happens below.

The most aggressive deployment he has seen is inside one company’s intranet: 3,000+ OpenClaw instances, one personal agent per employee, intermediate assistant layers between them, the whole thing sealed from the outside (his account; no independent verification). Preston-Werner’s takeaway from the same conversation is more personal: for the first time in his life, software asked him “how do you want me to change myself?” — installing its own dependencies, debugging its own environment, fixing its own bugs.

The open-source angle closes the episode: OpenClaw now runs under an independent nonprofit foundation with no ownership tie to OpenAI, matching the governance we verified in our September 29 OpenClaw Enterprise report. Openness is what lets agents be wired into a self-running company — closed products don’t hand you that thread.

What checks out and what doesn’t

Interviews blur self-reporting and fact, so we checked the load-bearing claims:

ClaimSourceVerification
Repo has ~3,000 PRs backloggedInterviewTrue: 3,354 open PRs measured 2026-10-08
Steinberger works at OpenAI, runs the foundation part-timeInterviewMatches the podcast’s official bio
OpenClaw belongs to an independent nonprofit foundationInterviewMatches the governance in our Sept 29 report
NVIDIA staffs daily vulnerability triageInterviewPartially verifiable: NVIDIA co-builds Enterprise; daily triage is interview-only
600 commits a day, 6,000 attack emailsInterviewNot independently verifiable; treat as self-reported
Claude Code username exfiltration chainInterviewOriginal disclosure not located; treat as cited anecdote
“Hand-written code is manual labor”; “in conversation with GitHub’s founder”Chinese write-up headlineEditorializing: the episode title is “send prompts”; Tom hosts, Peter is the only guest

That last row deserves a sentence of its own. The Chinese compilation puts two embellishments in its headline, while the episode’s actual claim is more precise: what shifts is the signal value of contributions — from code, which models regenerate anyway, to reasoning and context, which remain hard to fake. The two readings demand different responses. If “manual labor” were true, you’d wait for the models; under the episode’s version, you spend your judgment on prompts, architecture, and acceptance.

Borrowing this workflow

Three pieces are portable today. Give your main agent a blank-context reviewer and write the round budget (say, ten) into the flow so review triggers itself. Give your agents a sandbox where they can compile, install, screenshot, and click — off your main machine — mirroring whatever verification a human engineer would run. And if you maintain a project, say in CONTRIBUTING that bug reports should ship reproduction steps plus the prompt, and leave the code to the maintainer’s own agent.

Two background tracks are worth watching: sandboxing and monitoring are becoming industry components — NVIDIA’s Open Agent Safety platform and Google’s AX orchestrator are both competing for that slot — while OpenClaw Enterprise bets the governance layer on foundation stewardship. The episode is on YouTube and Apple Podcasts, the repo at github.com/openclaw/openclaw. Listen, then tell us whether auto-review makes it into your loop.