https://github.com/skorokithakis/stavrobot
Everything runs in containers (I run it on a server along with everything else), plugins have a permission system so eg the AI can read emails but not delete or send, etc.
I really like it, I run it as my main agent and it has been extremely helpful.
If it can only read but not act, it’s safer but less useful.
Zclaw is about running an agent in your embedded system.