Tiburon
Self-hosted AI agent with 18 tools across voice, vision, and automation. Runs on Telegram, executes scheduled cron jobs, and gates any high-impact action (file deletion, sending messages, restarting services) behind an explicit permission step before acting, instead of running unattended.
the problem
Most "AI agent" demos stop at answering questions. Turning that into something that runs unattended and touches real systems (a real Telegram account, a real filesystem, real scheduled jobs) raises a different problem: how do you get the benefit of autonomy without the risk of an agent doing something destructive on its own.
approach
Tiburon runs on the OpenClaw gateway framework with a multi-provider model fallback chain, so a single provider outage or rate limit does not take the whole agent down. It answers on Telegram, runs cron-scheduled jobs unattended, and reaches 18 tools spanning voice, vision, and automation -- but every high-impact action (deleting files, sending a message on the owner's behalf, restarting a service) stops and asks for explicit permission first, rather than assuming autonomy is always safe.
architecture
Multi-provider fallback
Model calls fall through an ordered chain of providers, so the agent keeps working when one provider is down, rate-limited, or out of credits.
Permission gate
Actions are classified by impact; anything that could cause real-world harm (deletion, outbound messages, service restarts) requires an explicit yes from the owner before it runs.
Telegram front end
The primary interface for day-to-day use: questions, approvals, and status all flow through a Telegram bot.
Scheduled automation
Cron-driven jobs handle recurring work (monitoring, reports, routine checks) without a human kicking each one off.