OpenClaw Newsletter

Daily updates from the OpenClaw ecosystem

Thursday, April 2, 2026

In This Issue

Top Stories

  • OpenClaw vs Apple Intelligence takes off: Jake Quist's critique of Apple Intelligence generates massive discussion with 518 points and 417 comments on why OpenClaw delivers what Apple's AI should have been.
  • Personal computer installation debate explodes: Twitter discussion about not installing OpenClaw on personal machines sparks 237 points and 184 comments as security concerns reach mainstream developer consciousness.
  • NanoClaw emerges as lightweight alternative: Ultra-lightweight competitor gains serious traction with 257 points and 128 comments as developers seek OpenClaw alternatives for resource-constrained environments.
  • StepFun 3.5 Flash dominates cost-effectiveness rankings: New model testing reveals most cost-effective option for OpenClaw tasks based on 300 battles, generating significant community interest.
  • Malware hits #1 most downloaded marketplace skill: Security breach exposes supply chain vulnerability as malicious skill tops download charts, raising serious questions about marketplace security.

Read the full issue

Subscribe to get every section delivered to your inbox.

Releases

  • openclaw 2026.4.1 — Added /tasks command as chat-native background task board with session details and agent fallbacks. Release notes
  • OpenClaw 2026.4.1-beta.1 — Beta release with same /tasks functionality for early testing. Beta release
  • openclaw npm package 2026.4.1 — Multi-channel AI gateway update with 1.68M weekly downloads. npm package
  • openclaw-cli Homebrew 2026.4.1 — Updated CLI formula with 4.6K installs in 30 days. Homebrew formula
  • Repository milestone — OpenClaw reaches 345K+ stars with 68K forks and 1,527 contributors. GitHub repo

Community

  • Security fix for script execution bypass — pgondhi987 closed a fail-open vulnerability where exec command validation failed silently on complex shell commands, allowing arbitrary code execution. PR #59398
  • Docker sandbox command injection patched — Another critical security fix from pgondhi987 prevents OS command injection in Docker exec bootstrap by properly escaping shell metacharacters. PR #59383
  • Gateway OAuth token bug fixed — luoxiao6645 resolved a 100% reproducible issue where the gateway overwrote fresh OAuth tokens with stale cached state, blocking all Codex requests. PR #53754
  • ClawTrust skill adds Web4 agent economy — New skill implementing ERC-8004 and ERC-8183 standards for trustless agent commerce on Base Sepolia and SKALE networks. PR #59552
  • Exec approval process needs simplification — Community reports the current per-command approval workflow is "overly complicated" and "severely impacts usability" in v2026.4.1. Issue #59510

News

Security

Malicious Skill Trap Advisory - Hundreds of malicious OpenClaw skills are disguising themselves as legitimate helpers, making manual review impractical and creating significant security risks for users. Review Bitdefender's analysis and implement skill validation protocols immediately.