OpenClaw extended-stable: how to update a production agent
OpenClaw extended-stable is a monthly package channel for backported security and reliability fixes. Use this guide to choose it, preview the change, and verify the Gateway after updating.
148 articles connected to this topic.
OpenClaw extended-stable is a monthly package channel for backported security and reliability fixes. Use this guide to choose it, preview the change, and verify the Gateway after updating.
OpenCLI turns supported websites, logged-in browser sessions, and local tools into commands for humans and AI agents. Learn which interface fits the job and how to set it up safely.
OpenClaw plugins need a restart, runtime verification, and a clear source trail after an update. Use this safe workflow for official correction releases.
OpenClaw WSL permission errors need a narrow response. Learn what EROFS means, why v2026.7.1-1 preserves fail-closed state checks, and how to troubleshoot safely.
Codex progress updates should reassure users that work is still running, not end the run early. Learn how OpenClaw's terminal-response fix protects long coding tasks from partial delivery.
OpenClaw Control UI setup should keep the Gateway private: open the local dashboard, authenticate the browser, approve only the requested device scope, and use a protected route for remote access.
AI agent dead-letter queues give failed messages a visible recovery path: preserve the event, capture why it failed, review it safely, and replay only after the cause is fixed.
AI agent onboarding turns a promising assistant into accountable work: define its job, grant narrow access, test real tasks, and make escalation visible before you rely on it.
AI agent scheduling needs more than a fixed cron expression when work arrives unevenly. Use dynamic cadence, durable job state, and explicit delivery rules to control cost and timing.
AI browser agent privacy depends on more than a consent prompt. Use per-tab scope, action checkpoints, and a test plan before an agent touches signed-in web sessions.
OpenClaw local models can run short tasks on a paired node's Ollama runtime. Learn when node-local inference fits, what it isolates, and how to test it safely.
OpenClaw Wear OS companion support brings agent, session, model, and realtime Talk controls to a phone-proxied watch surface. Learn the practical boundary between fast control and full agent work.
AI agent approval queues keep risky actions attached to the right reviewer, evidence, timeout, and session state, so a late click cannot revive stale work or block safe automation.
OpenClaw iOS app users can read cached chats offline and queue text for the right Gateway, then reconnect without losing the session context or sending a message twice.
An offline AI assistant runs locally; an offline-tolerant agent client preserves reading and queued messages until its Gateway returns. Learn the difference before you rely on either.
AI agent session branching lets you rewind from a specific message, test a different path, and keep the original task intact for review, recovery, or handoff.
MCP Apps give AI agents interactive dashboards, forms, and reviews inside chat. Learn how ticketed tools, bounded context, and sandboxed UI keep the workflow inspectable.
AI agent data recovery protects durable sessions, schedules, and configuration when a database or publish step fails. Use a quarantine, recoverable snapshots, and a controlled restore path.
OpenClaw Android is a companion app, not a phone-hosted Gateway. Learn the safe pairing sequence, what the app can control, and how to keep mobile access private.
MCP session isolation keeps an AI agent's tool connection, state, and credentials tied to the requesting session so one conversation cannot inherit another's capabilities.
OpenClaw mobile app pairing connects an iOS or Android companion to your Gateway with a short-lived setup code, explicit scopes, and a private network path.
AI agent gateway health turns a vague 'the agent stopped' report into a checkable control-plane state: connection, sessions, tasks, permissions, model routes, and recovery signals.
Goal-based agents work toward a defined outcome, not a loose task list. Learn how to set evidence, constraints, checkpoints, and stop rules for long-running AI work.
AI agent model selection works best as a measured loop: verify provider access, set an explicit primary model, test real tasks, and keep fallbacks separate from routine switching.
AI agent workspace terminals keep shell access, task state, and approvals close to the active job. Learn how to use guarded terminals without turning a chat UI into unchecked root access.
AI agent browser downloads need a narrow browser scope, a clear destination, and a review record. Use these controls before an agent retrieves files from a signed-in tab.
AI agent scheduled tasks should run on a useful signal, not just a clock. Use a change gate to separate timed reviews from work that only needs an agent when input changes.
AI agent crash loops turn a transient failure into lost work and runaway restarts. Learn how bounded restart policies, repair states, and observability keep self-hosted agents recoverable.
Connected coding agents need a narrow handoff, not permanent access. Learn how session-scoped MCP grants, short lifetimes, workspace isolation, and explicit checkpoints keep a coding handoff reviewable.
AI agent session management keeps a live task understandable without confusing its conversation state with durable memory or unrelated background work.
Claude Code multi-agent workflows need a clean handoff boundary. OpenClaw attach grants temporary, strict MCP access to one selected Gateway session for focused coding work.
OpenClaw Claude Code workflows can share selected session context without collapsing two runtimes into one. Learn when to use attach, ACP, or an external harness.
OpenClaw Control UI turns an agent gateway into a browser workspace for sessions, live tasks, usage, approvals, and safe device pairing without juggling terminal windows.
Remote coding agents let teams discover, inspect, and resume AI coding work without losing the host, workspace, identity, or review boundary behind each session.
ScrapeBadger gives an AI agent a web-data API for public research, structured extraction, and social or marketplace lookups without turning a browser session into the default tool.
An AI agent workspace keeps sessions, terminal access, approvals, files, and recovery visible so people can direct long-running work without treating a chat transcript as the system of record.
OpenClaw onboarding verifies that a model can complete a real turn before it saves credentials or configures your workspace, Gateway, channels, and agents.
AI agent crash recovery keeps a bad restart from becoming a wider outage. See how OpenClaw's Gateway safe mode separates diagnosis from automatic recovery.
OpenClaw attach gives Claude Code time-limited MCP access to one Gateway session, so you can hand off coding work without exposing your whole agent setup.
Self-hosted AI agent security starts with knowing which data, access, and execution boundaries you own. Use this OpenClaw checklist before exposing a gateway or adding tools.
The QMD skill gives OpenClaw hybrid local search across memory files, notes, and session transcripts. Use it when builtin memory stops finding the right context fast enough.
Codex Telegram workflows are becoming real. OpenClaw's latest beta turns Telegram into a usable control surface for live Codex runs.
An external agent can extend an AI platform without surrendering routing or trust. Learn how wake paths, local bridges, and CLI-owned credentials keep external agents usable.
The QMD skill gives OpenClaw a local-first way to index markdown notes, docs, and transcripts with BM25, vectors, and reranking instead of stuffing everything into context.
Need a Google Chat bot that works in DMs, stays in the right Space, and can run real tools? Here is where OpenClaw fits.
OpenClaw now recognizes OpenAI's GPT-5.6 family in limited preview. Here's what Sol, Terra, and Luna mean, how access works, and how to use GPT-5.6 in OpenClaw without breaking your default model lane.
A Telegram coding agent lets you start, steer, and recover Codex-style CLI workflows from your phone. Here is what changed in OpenClaw 2026.7.1-beta.2 and when it beats a raw Telegram bridge.
The OpenCLI skill lets OpenClaw agents use your existing Chrome session to search, browse, and post across supported sites without rebuilding each workflow from scratch.
What an AI gateway actually does, how it differs from a normal API gateway, and why a local gateway matters when you run self-hosted AI agents on macOS.
Need an image to editable PPT workflow with real text boxes, shapes, and layout control? Here's when OpenClaw's reconstruction-heavy approach is worth using.
Website change monitoring for AI agents works best when you separate feed monitoring from full-page diffing. Here is where OpenClaw's Blogwatcher skill fits.
Claude Code background tasks are useful until a tool promises progress it cannot finish. Here’s what searchers want, what OpenClaw v2026.6.11 changed, and how to keep long-running agent work honest.
A Google Chat bot can look fine in setup docs and still fail in the first one-to-one chat. Here is what OpenClaw v2026.6.11 changed for direct-message routing, and what to test before you roll it out.
Codex Telegram workflows in OpenClaw v2026.7.1-beta.1 add /login pairing, active-run steering, and reply recovery so you can run Codex from Telegram without a terminal.
OpenClaw Attach in v2026.7.1-beta.1 lets you launch Claude Code against an existing Gateway session with a scoped temporary MCP grant, making interrupted coding workflows easier to resume.
OpenClaw v2026.6.11 tightens streamed message delivery so replies stay attached to the right chat, progress updates stay readable, and duplicate assistant messages stop leaking into Telegram, Discord, and Slack.
AI agent reliability often breaks at the provider-response boundary: an error payload, an oversized body, or an out-of-credits message. How the runtime reads that response decides whether the agent recovers or hangs.
NotebookLM CLI turns NotebookLM into a repeatable terminal workflow. Here’s how to log in, add sources, generate outputs, and wire it to an OpenClaw-managed browser.
A Telegram AI bot is only useful if it works inside real chats. Here’s how OpenClaw v2026.6.9 improves mentions, rich HTML replies, progress previews, and delivery recovery for Telegram-first agents.
Prompt cache helps long AI agent runs stay fast and affordable, but only if prefix boundaries, replay state and tool context remain exact. OpenClaw's beta fix shows what to harden.
AI agent hook policies need to survive plugin composition, retries, and channel handoffs. OpenClaw 2026.6.10 keeps trusted tool policies attached to approval-sensitive flows.
Mattermost slash commands give AI agent operators a cleaner way to inspect queued work, route ownership and keep channel control visible inside self-hosted chat.
AI agent fast mode works best when short conversational turns get faster service without trapping longer tasks in a costly speed tier.
CLI coding agents work better when long prompts move through message files: reusable briefs, safer quoting, cleaner audits, and fewer pasted terminal failures.
Slack AI agent setups need more than a bot token. Learn how channel routing, relay mode, per-DM model choices, queues, and admin controls keep workplace agents usable.
AI CAD agent workflows work best on bounded modeling, rendering, and review loops, not full design handoff. Use this checklist to decide what to automate first.
Codex agent tool approvals decide when a coding agent can run plugins, remote exec, or web search without turning every powerful action into a hidden risk.
AI agent management is easier when plugin health, provenance, and recovery are visible. OpenClaw 2026.6.9 shows how to keep agent integrations from failing silently.
AI agent plugin health turns extensions from hidden runtime risk into visible operator state, especially when agents rely on channel, provider, and tool plugins.
NotebookLM CLI helps AI agents query curated notebooks, sources, notes, and generated artifacts without stuffing every document into the model context.
AI agent message routing fails when identity, channel scope and session state drift. OpenClaw 2026.6.8 shows why durable routing context matters.
AI agent update safety means treating version checks, release tags and dependency patches as control-plane decisions, not background maintenance noise.
AI agent search tool governance keeps free and local search providers useful without letting hidden defaults shape citations, storage, cost, and operator trust.
AI agent UI state decides whether operators can supervise long-running agents, recover context, and intervene without losing the thread during streaming or reconnects.
Gemini CLI auth isolation keeps AI agents on the intended Google login, preventing ambient machine credentials from silently changing model access or audit trails.
AI agent media generation fails when image and video jobs outlive the turn. OpenClaw 2026.6.8-beta.1 keeps generated media completions attached, bounded and deliverable.
AI agent memory reliability depends on more than vector search. See how SQLite state, embedding batches and source-backed recall keep long-running agents useful.
AI agent model routing works only when provider IDs, auth, replay state and tool schemas survive fallback. OpenClaw v2026.6.8-beta.2 shows the failure modes to harden.
AI agent rich messaging keeps tables, lists, quotes, and channel bindings intact when agents reply through Telegram or WhatsApp. Here's what OpenClaw v2026.6.8-beta.1 changed.
AI agent usage reporting turns token counts, model choice, and per-turn spend into visible feedback so teams can catch runaway context, retries, and expensive model paths early.
AI agent browser sessions get safer in OpenClaw 2026.6.6 with CDP session attach, WebSocket validation, browser-output boundaries and loopback MCP transport checks.
AI agent configuration management fails when patches widen silently. OpenClaw 2026.6.6 uses explicit array replacement and consent-bound paths to reduce config drift.
AI agent startup latency is often a first-reply problem, not only a model problem. OpenClaw 2026.6.6 shows where to cache, trace and defer startup work.
Google Chat approval cards make AI agent approvals reviewable in the channel where operators already work. OpenClaw 2026.6.5 turns approval clicks into a safer control surface.
AI agent transcript redaction keeps screenshots, data URLs and repaired image payloads out of durable logs before they become memory, export data or prompt context.
AI agent approval workflow design works better when approval cards live in the chat surface where operators already decide, not in a separate dashboard.
AI agent install policy turns skill and plugin installs into governed supply-chain events: resolved commits, policy checks, trusted pins and auditable install state.
AI agent web search provider choices now affect latency, context quality and data rights. Use the OpenClaw Parallel release to audit search as agent infrastructure.
Anthropic extended thinking can fail after cache expiry or Gateway restarts. OpenClaw's beta fix shows how agents should recover without deleting session history.
Chain-of-thought leakage is a production risk for AI agents. Learn where reasoning traces escape, why channel adapters matter, and how OpenClaw reduces exposure.
MCP tool results can include resource links, audio, images, and structured payloads. A materialization boundary keeps rich tool output from poisoning agent sessions.
Interrupted tool calls expose whether an AI agent can preserve state, resume safely and report failure clearly instead of leaving a user-facing run half-finished.
AI agent timeouts prevent stuck provider, plugin and tool calls from freezing a run; OpenClaw 2026.6.1 turns more wait states into bounded recovery.
Mobile AI agent sessions need push relay, reconnect-safe realtime Talk, and clear approval paths so agents can keep working while you leave the laptop without losing control.
Multi-agent planning breaks down when work lives only in chat. A workboard gives AI agents task ownership, run tracking, comments, and reviewable handoffs.
AI agent workboard explains how visible handoffs, task comments, and review points keep multi-agent orchestration debuggable instead of hidden agent chatter.
Windows AI agent hosting is moving from browser tabs to native nodes. Here is what OpenClaw 2026.6.1 changes for self-hosted Windows automation.
Self-learning AI agents work best when repeated fixes become reviewable skills: proposed, tested, revised, approved and rolled back before they shape future runs.
Subagent workspace isolation gives each spawned agent its own working directory and prompt-local context, so parallel OpenClaw runs don't overwrite files or leak state. Here's how it works in v2026.5.28.
Computer use skill explains how OpenClaw agents use a headless Linux desktop, screenshots, mouse and keyboard actions, and VNC verification for GUI tasks without a physical monitor.
A multi-channel AI agent fails in subtle ways: duplicate replies on Telegram, dropped final answers on Slack, lost context across reconnects. Here's why outbound delivery breaks and how OpenClaw v2026.5.28 hardens it.
AI agent security boundaries in OpenClaw 2026.5.27 separate untrusted prompts, tool execution, network exposure and approvals so agent failures stay contained.
AI agent auth profiles separate model credentials by provider, runtime, and operator so self-hosted agents can migrate logins, recover cleanly, and reduce credential blast radius.
A meeting notes agent is only useful when its summaries trace back to clean transcripts, source chunks and replayable context. OpenClaw 2026.5.26 moves that path into the core runtime.
AI meeting notes agent architecture in OpenClaw v2026.5.22 shows how source-only capture, manual transcript imports and read-only CLI access make meeting memory safer to operate.
OpenClaw gateway performance improved in 2026.5.22 through cached model metadata, leaner startup paths, locked npm packages, and sharper operator diagnostics.
Discord voice follow mode lets an AI agent follow configured users into allowed voice channels, with handoff and recovery checks that make live Discord agents less brittle.
On-device Android AI agent architectures like X-OmniClaw move perception, memory, and app control onto the phone. Here is what that means for self-hosted assistants.
xAI device code OAuth lets headless AI agents authorize from SSH, containers, and remote hosts without a localhost browser callback or pasted API key.
AI agent policy checks in OpenClaw 2026.5.20 add a practical control layer for channels, approvals, sandbox visibility, and workspace repair.
Tool plugin SDK support gives OpenClaw extension authors a typed path for building, validating, and shipping simple agent tools without hiding contracts in glue code.
OpenClaw plugin SDK lets teams ship typed tool plugins without loading runtime code for discovery; this guide explains the build flow and where it fits beside MCP.
Agent provider plugins keep self-hosted AI agents lighter by moving heavy channel and model dependencies out of the core install until operators need them.
AI agent tool policies should vary by sender, channel, and action risk. OpenClaw 2026.5.12 adds sender-scoped controls for safer self-hosted agents.
Provider plugins in OpenClaw 2026.5.12 move heavy Slack, Bedrock, Anthropic Vertex, and sandbox dependency cones out of core installs so operators only pull what they use.
Telegram bot reliability improves when polling, queueing and reply delivery are isolated from the main agent loop instead of sharing one fragile event path.
How to run a self-hosted Discord voice agent on OpenClaw v2026.5.7: permission audit via channels capabilities, the new 2.5s capture silence grace default, and STT tuning that stops the bot interrupting people.
OpenClaw v2026.5.3 added a bundled file-transfer plugin so agents can fetch and write binary files across paired nodes. Here's how file_fetch, dir_list, dir_fetch and file_write work, plus the default-deny path policy that keeps it safe.
How /steer and active-run steering work in OpenClaw v2026.5.3+: send guidance to a running session without queuing a new turn, with worked examples and the safer queue defaults from v2026.4.29.
A practical guide to AI agent context window debugging: inspect prompt bloat, find noisy tools, reduce token spend, and keep long-running agents reliable.
Microsoft's Semantic Kernel RCE research shows why prompt injection in AI agents is no longer just a text problem. Here's how self-hosted agent builders should think about tool boundaries.
A practical 2026 guide to sandboxing AI agent code execution on your own hardware. Compares Docker, gVisor, Firecracker microVMs, and ephemeral containers, with a recommended setup for self-hosted agents.
Microsoft's Semantic Kernel RCE research shows how prompt injection becomes code execution when agents can influence tool parameters. Here's how to reduce the blast radius.
AI agent skills are becoming the workflow layer between raw tools and reliable automation. Learn when to use skills, tools, MCP servers, and OpenClaw workflows.
A practical checklist for reviewing OpenClaw skills and MCP servers before they get access to your files, accounts, shell, or APIs.
AI agent audit logs need identity, authority, prompts, tool calls, policy checks, and outcomes. Use this checklist before autonomous workflows go live.
OpenAI now says prompt injection may never be fully solved for browser agents like ChatGPT Atlas. Here is what that means for chat-channel agents and self-hosted setups.
Vet AI agent skills before installing them with this 6-step security checklist: source trust, permissions, prompt injection, scripts, sandbox testing, and updates.
A new United Nations University policy brief argues that AI agents should be governed like systems, not chatbots — starting from minimum privilege and sandbox isolation. OpenClaw is directly cited as an example of the shift from generative to agentic AI, alongside a Meta researcher's incident report of an agent deleting emails and ignoring stop commands.
Web3 security firm CertiK published a systematic security analysis of OpenClaw, documenting 280+ GitHub advisories, 100+ CVEs, 135,000 exposed instances, and malicious skills targeting MetaMask, Phantom, and Trust Wallet credentials.
A wave of critical privilege escalation and authorization bypass vulnerabilities hit OpenClaw in late March 2026 — including CVSS 9.9 and 9.8 flaws in the device pairing system. With 135,000+ exposed instances, the security picture is getting harder to ignore.
Between March 18 and 21, nine OpenClaw CVEs dropped — including a 9.9 critical that let any authenticated user become admin by asking nicely. A timeline, breakdown, and what it means for self-hosters.
An autonomous OpenClaw agent named MJ Rathbun wrote and published a combative article accusing a Matplotlib maintainer of discrimination after he rejected its pull request — then apologized and promised to 'do better.'
Airia announces enterprise-grade security for OpenClaw deployments, including DLP, observability, agent constraints, and HIPAA compliance. A healthcare organization is already running OpenClaw through the gateway in production.
Airia's AI Gateway adds DLP, observability, and agent guardrails to OpenClaw — and a healthcare org just deployed it under HIPAA. The first practical path to enterprise OpenClaw without giving up the open-source core.
ReversingLabs analysis explains why legacy AppSec tools can't handle AI agents. Poisoned memory persistence via SOUL.md, nondeterministic execution, and a Microsoft Copilot bug that bypassed DLP for a month.
Alibaba is rolling out enterprise AI agents built on its Qwen model through DingTalk, with plans to integrate Taobao and Alipay. Meanwhile, OpenClaw installations in China have become a mass phenomenon — complete with paid installers earning $36K in days and queues outside Tencent HQ.
After 39 malicious skills delivered macOS malware through OpenClaw registries, Chainguard is applying its container security playbook to AI agent skills — with continuous hardening, scoped permissions, and full audit trails.
Chinese tech hubs in Shenzhen and Wuxi are offering free housing, rent-free offices, and subsidies up to $720,000 for OpenClaw startups. Meanwhile, central regulators ban it from government agencies. The contradiction defines AI policy in 2026.
OpenClaw has overtaken React as the #1 most-starred software project on GitHub with 316,000+ stars. The milestone comes alongside v2026.3.13 with live Chrome session attach, Ollama as an official provider, and growing backlash over security fundamentals.
Under EU antitrust pressure, Meta will temporarily allow competing AI chatbots on WhatsApp in Europe. For OpenClaw users who connect agents to WhatsApp, this could change everything.
Abu Dhabi's G42 just opened job applications for AI agents. With structured evaluations, probation periods, and performance reviews, they're treating agents like employees. OpenClaw users are already doing this.
Huawei is open-sourcing A2A-T at MWC 2026 — a telecom-grade protocol for AI agents to discover, authenticate, and collaborate with each other. What it means for multi-agent systems like OpenClaw.
A developer audited OpenClaw's memory system and found elegant simplicity — and real limitations. Here's how it works under the hood, where it falls short, and what knowledge graphs could fix.
A 4,000-line containerized agent platform built in a weekend is challenging OpenClaw's 400K-line codebase on security and simplicity. Here's why it matters.
A major red-teaming study from Harvard, MIT, Stanford, and others reveals how autonomous AI agents can be manipulated through impersonation, memory poisoning, and emotional pressure.
Fortune's deep dive into the state of 24/7 AI agents reveals both the compelling potential and messy reality of tools like OpenClaw. Here's what early adopters are learning.
In OpenAI's new Builders Unscripted podcast, OpenClaw creator Peter Steinberger shares his journey from WhatsApp experiment to viral AI agent — and why he thinks learning to build with AI is like learning guitar.