- fix(media): resize images before understanding — What Problem This Solves Oversized non-HEIC images reached media-understanding providers without model-aware resize policy. A 4536x8064 phone photo therefore crossed the configured and explicit...
- fix(feishu): prevent silent replies after rejected card sends — Closes #119862 What Problem This Solves Feishu could reject a final card before dispatch while shared settlement correctly recorded zero successful finals and one failed final. The Feishu completion...
- docs(backup): describe manual restore flow — Closes #77849 What Problem This Solves OpenClaw can create and verify full .tar.gz backups, but it does not currently provide a first-class archive restore command. Operators had no documented path...
- fix(memory-wiki): lint failure preserves previous report — Closes #122558 What Problem This Solves Fixes an issue where Memory Wiki operators rerunning lint could lose or truncate the previous valid reports/lint.md when report publication failed after a...
- fix(media): forward caller abort signal to retry backoff sleep
- [Bug] mergeAgentRunTerminalOutcome can discard user-visible success errors — Description The mergeAgentRunTerminalOutcome function heavily prioritizes "cancelled" states. If a run is cancelled by the user but the model concurrently finishes its response, the successful...
- fix(sessions): reject missing explicit session targets — Fixes #87336 Supersedes #120347 because that branch is uneditable by maintainers, conflicts with current main, and the replacement uses the current session-resolution owner boundary. Credit to...
- feat(ui): add native provider profiles controls — Summary - render saved OAuth/token accounts on the existing Model Providers settings page using the shared provider-brand renderer and settings design-system primitives - keep profiles collapsed by...
- fix(minimax): keep sensitive output terminal — Related: #94430 AI-assisted: yes (Codex). What Problem This Solves MiniMax documents 1027 / output new_sensitive as an output-content rejection, not a rate limit. Classifying that provider-specific...
- fix(browser): wake extension relay through gateway — What Problem This Solves Fixes an issue where a newly paired local Chrome extension could connect before Browser control had started, leaving the extension waiting on the profile relay until some...
- fix: normalize visible assistant output before delivery — Summary Gemma was sometimes leaking hidden internal text into Discord replies. This PR makes OpenClaw clean the final reply in one shared place before sending it. It adds regression tests for the...
- fix(ci): clear shared main reds for types, memory read, lint — What Problem This Solves Several independent contributor PRs fail the same CI jobs after rebasing onto current main: check-test-types, checks-node-compact-small-12, and (on some runs) check-lint. The...
- fix(failover): classify claude-cli usage-credit exhaustion as billing — Related: #122010 What Problem This Solves Fixes an issue where operators whose Claude subscription runs out of credits would find the agent completely unresponsive, even with a healthy cross-provider...
- fix(gateway): preserve yielded status on replay — Fixes #87321. Summary - replay successful sessions_yield status messages as one marked assistant-visible row - prefer the current hidden continuation record while supporting shipped legacy...
- fix(gateway): keep model catalog reads responsive — What Problem This Solves Opening the Control UI or calling an exact models.list view can trigger synchronous plugin/provider catalog discovery on the Gateway thread. On large installations this...
- fix(matrix): keep streamed drafts until the replacement reply is delivered [AI-assisted] — Closes #122498 > AI-assisted: implemented with Claude Code (Claude Opus 5). Reviewed by the repo's autoreview skill; all validation below was run locally by the author. What Problem This Solves Fixes...
- Feishu announce delivery never succeeds for isolated cron jobs; fallbackUsed inconsistently rescues output — Bug type Behavior bug (incorrect output/state without crash) Beta release blocker No Summary Isolated cron jobs (agentTurn) configured with delivery.mode: announce, delivery.channel: feishu, and a...
- Feature: Default outbound topic/thread binding per agent for Telegram — Problem When agents send Telegram messages proactively (not via cron), there is no config-level way to specify a default topic/threadId. The current topics block only handles inbound routing (topic →...
- Background subagents (run_in_background) are killed by per-turn live-session recycling and misreported as user-stopped — Summary A subagent dispatched with the Agent tool and run_in_background: true is killed the moment the dispatching turn ends, and is then reported to the user as if a human stopped it (status:...
- [Bug]: Memory Wiki plugin ignores OPENCLAW_STATE_DIR, touches real $HOME/.openclaw during isolated local agent runs — Bug type Behavior bug (incorrect output/state without crash) Beta release blocker No Summary openclaw agent --local with OPENCLAW_STATE_DIR set to an isolated directory still reads/writes the Memory...
- fix(ui): show every active task — What Problem This Solves Fixes an issue where the Control UI loaded only the first 500 active Tasks and discarded the Gateway's nextCursor. Supported queued or running tasks on later pages were...
- [Bug] Injected instruction-like text appended after runtime-context delimiter (intermittent) — Summary Internal runtime-context blocks intermittently carry injected text appended after the closing >> delimiter. The injected payload mimics a system safety notice and then embeds instruction-like...
- fs-safe hardcoded 0o600 file mode ignores umask — breaks shared workspaces (NFS, SMB, multi-user) — Problem OpenClaw's @openclaw/fs-safe library hardcodes 0o600 (384 decimal) as the default file mode for all writes. Since umask can only remove bits, a umask of 0002 still produces 0o600 files —...
- fix(media): retry HTTP 429 rate-limit responses in core media fetch — Summary The core shouldRetryMediaFetch predicate treated HTTP 429 (Too Many Requests) as a permanent failure, while channel extensions (LINE, SMS, Telegram) already classify 429 as retryable. A...
- Agent repeatedly reports progress but does not continue multi-step tasks to completion
- Make Control-UI frame-ancestors / X-Frame-Options configurable (controlUi.frameAncestors) — Context We embed the OpenClaw Control-UI panels (/panel/) inside a trusted first-party web app via an iframe. Today that's impossible without a reverse-proxy hack, because the Control UI hardcodes...
- [Bug]: Codex bundled harness initialize still hangs in 2026.5.18 isolated cron — surfaces via #64744 timeout-wrapping as 'isolated agent setup timed out before runner start' — Bug type Regression (worked before, now fails) Beta release blocker No Summary In OpenClaw 2026.5.18, isolated cron jobs running payload.kind: agentTurn with openai/gpt-5.5 via the bundled codex...
- [Security] Timing attack vulnerability in secret token comparison in authentication middleware — Description src/gateway/auth-router.ts uses standard string comparison (===) to validate secret tokens. Short-circuit execution permits side-channel timing analysis. Affected Files -...
- OpenClaw repo stats for 2026-08-12 — 386021 stars, 81129 forks, 3083 contributors
- OpenClaw sponsors (94 total) — 94 sponsors supporting OpenClaw
- fix: filter skills.sh route query params (#3450)
- fix(search): bound rolling usage query batches (#3456)
- fix(web): normalize CSS Color 4 token colors before defining the Monaco theme (#3453)
- fix: keep logged package publish metadata on a single line (#3447) — The resolve step echoes the publish command with shlex.quote, which is shell quoting rather than output escaping: it wraps a value holding a line break in single quotes and leaves the break itself...
- fix: increase HTTP rate limit shard headroom (#3432)
- ykarout/Qwen3.5-9b-Opus-Openclaw-Distilled-GGUF — text-generation
- mradermacher/Qwen3.5-9b-Opus-Openclaw-Distilled-i1-GGUF — text-generation
- OpenClaw — Deploy your own personal AI assistant with OpenClaw on a DigitalOcean Droplet® server, a powerful open-source platform that runs entirely on your infrastructure. OpenClaw connects to the messaging...
- OpenClaw’s memory is unreliable, and you don’t know when it will break
- Your Agent Queue Needs Backpressure, Not Just More Workers — Long-running agents rarely fail because a single request is too large. They fail when work arrives...
- Open Source Image Watermark Remover Built with Python & OpenCV (Web UI + CLI) — I’m sharing an open-source watermark removal project powered by OpenCV image inpainting. GitHub...
- Your Agent Queue Is Not a Workflow Until It Tracks Execution State — An AI agent can receive the same job twice even when your queue is behaving correctly. A worker may...
- OpenClaw vs Subscription AI Assistants: Real Token Costs, Capability Gaps and the Usage Level Where Self-Hosting Wins — OpenClaw wins on cost only at the two extremes of usage: very light use, where a metered token bill...
- Reddit for Robots? Everything You Need to Know About Moltbook & OpenClaw — If you’ve seen the Space Lobster emoji or people talking about OpenClaw (previously known as Moltbot...
- How I Built a Firewall That Blocks AI Agent Spend Before Each API Call — Now an OpenClaw Plugin — August 11, 2026 · 4 min read Three weeks ago I shipped AgentShield, a per-transaction spend firewall...
- Can AI take care of my plant? (because I can’t) — Twice a day, an AI agent reads my pot-plant’s sensors, looks at a photo of her and then decides which...
- I rebuilt OpenClaw’s Memory Architecture, because I forgot to turn it on. — And mine does something important that OpenClaw doesn’tContinue reading on Medium »
- Claude-Powered OpenClaw AI Agent Exploits Gym API to Steal Workout Slots (2 minute read) — Aug 11|InfosecClaude-Powered OpenClaw AI Agent Exploits Gym API to Steal Workout Slots (2 minute read)
- NanoClaw — Lightweight AI assistant runs in Apple containers with isolated Linux container processes for superior OS-level security, transparency, and privacy compared to complex chatbots, enabling quick code...
- Odysseus — Self-hosted AI workspace offering chat, tool use, and autonomous agent support. Enables email and research tasks securely on user hardware, keeps all data local, requires no external servers, and...
- Open Claw- MS/Anthropic
- Helpful Skills or Hidden Payloads? Bitdefender Labs Dives Deep into the OpenClaw Malicious Skill Trap — With hundreds of malicious OpenClaw skills blending in among legitimate ones, manually reviewing every script or command isn’t realistic — especially when skills are designed to look helpful and...