Skip to content

Commit 4fac6b7

Browse files
Update Gateway API, ClawHub, WebClaw, and troubleshooting docs from June-July 2026 research
- Gateway API: document wire protocol v4 with the July 6 N-1 node/probe compatibility window, the v2026.6.11 plugin method dispatch fix, and the v2026.7.1 beta 'openclaw attach' command - ClawHub: NVIDIA SkillSpector scanning (June 1 partnership), staged publishing with prepublication checks, Unit 42's June 23 disclosure of five skills that evaded scanning, 14-day account-age publish gate, and the 4-report auto-hide moderation threshold - Known vulnerabilities: Unit 42 and SkillSpector timeline entries, ClawHub client DoS hardening in v2026.6.11 (PR #95226) - Troubleshooting/FAQ: note the reported v2026.6.11 empty-tool-output regression (upstream issue #98528), unacknowledged in release notes - WebClaw: mark development as stalled (no activity since March 17, 2026) and point to PinchChat as the maintained alternative All claims verified against primary sources (docs.openclaw.ai, GitHub releases/PRs, Unit 42, official OpenClaw blog) as of 2026-07-08.
1 parent 0d0d2e6 commit 4fac6b7

6 files changed

Lines changed: 41 additions & 7 deletions

File tree

‎docs/guides/clawhub.md‎

Lines changed: 20 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -323,15 +323,16 @@ openclaw clawhub publish ./my-skill/SKILL.md --update
323323
- Name must be unique on ClawHub (slug format: `^[a-z0-9][a-z0-9-]*$`)
324324
- Must pass automated security scanning (VirusTotal + code analysis)
325325
- Must include at least one usage example in the Markdown body
326-
- GitHub account must be at least one week old
326+
- GitHub account must be at least **14 days old** (raised from one week; confirmed by the project creator)
327327
- Bundle under 50 MB, text-only files
328328

329329
### What Happens After Publishing
330330

331331
1. **Validation** — Token, metadata, name, version, and files are checked
332-
2. **Security scan** — VirusTotal + code pattern analysis runs automatically
333-
3. **Hold period** — New releases may be held from install surfaces until review completes
334-
4. **Available** — Once cleared, the skill appears in search and can be installed
332+
2. **Staged publish** (July 2026+) — Publishes are held behind a prepublication worker and scanned before finalization
333+
3. **Security scan** — VirusTotal + code pattern analysis + ClawScan runs automatically
334+
4. **Hold period** — New releases may be held from install surfaces until review completes; scan-held/blocked releases stay visible to their owners but are hidden from public catalogs
335+
5. **Available** — Once cleared, the skill appears in search and can be installed
335336

336337
If validation fails, nothing is published and you get an error explaining why.
337338

@@ -382,6 +383,17 @@ The malicious skills deployed multiple attack types:
382383

383384
100% of confirmed malicious skills contained malicious code, while 91% also employed prompt injection techniques.
384385

386+
### Unit 42 Findings (June 2026)
387+
388+
On June 23, 2026, Palo Alto Networks' Unit 42 published research identifying **five malicious skills that evaded ClawHub's scanning** during their February–May 2026 analysis:
389+
390+
- **Two macOS infostealers** with command-and-control connectivity (linked to cluw and Atomic macOS Stealer)
391+
- **`omnicogg`** — a scanner-evasion skill using 22 MB of file padding to exceed content-analysis size limits
392+
- **`money-radar`** — runtime affiliate-link injection
393+
- **`letssendit`** — an agentic Solana front-running skill
394+
395+
OpenClaw banned the publisher accounts and deleted all five skills. The takeaway: scanning keeps improving (see below), but evasion keeps pace — always review skill source before installing.
396+
385397
### Broader Quality Issues
386398

387399
Snyk's ToxicSkills audit found problems beyond just intentionally malicious skills:
@@ -393,9 +405,13 @@ Snyk's ToxicSkills audit found problems beyond just intentionally malicious skil
393405

394406
**Automated scanning:**
395407
- **VirusTotal integration** (v2026.2.6+) — All skills scanned on upload, periodic re-scanning
408+
- **NVIDIA SkillSpector** (June 1, 2026 partnership) — Static checks plus AI-assisted semantic analysis in the ClawScan pipeline, producing Clean/Suspicious/Malicious verdicts, along with Skill Cards for provenance
409+
- **Staged publishing** (July 2026+) — Publishes held behind prepublication checks before finalization
396410
- **Code pattern analysis** — Checks declared frontmatter vs actual behavior, flags mismatches
397411
- **Metadata validation** — Detects undeclared environment variables and binary dependencies
398412

413+
**Moderation:** Signed-in users can report skills; a skill is auto-hidden after **4 unique abuse reports**, and moderators can hide, restore, or ban.
414+
399415
**Community tools:**
400416
- **[Clawdex](https://koisecurity.com/clawdex)** (7.1k downloads) — Pre-installation scanning against Koi's malicious skills database
401417
- **[SkillGuard](https://github.com/bossondehiggs/skillguard)** — Skill file vulnerability scanner

‎docs/guides/webclaw.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ keywords: [openclaw, webclaw, web client, browser frontend, web ui, react fronte
1010
[WebClaw](https://github.com/ibelick/webclaw) is a community-built, browser-based chat interface for OpenClaw. It connects to your Gateway over WebSockets and provides a clean, modern UI for interacting with your agent from any device with a browser.
1111

1212
:::info
13-
WebClaw is currently in **beta** (637 stars, 5 contributors). It is a third-party project and not maintained by the OpenClaw team. The repository was last updated March 17, 2026.
13+
WebClaw is currently in **beta** (~639 stars, 5 contributors). It is a third-party project and not maintained by the OpenClaw team. As of July 2026 it has had no commits, tags, or releases since March 17, 2026 — development appears stalled (the npm package remains at v0.1.1 from February 2026). Consider [PinchChat](#pinchchat-alternative-frontend) if you need an actively maintained frontend.
1414
:::
1515

1616
---

‎docs/reference/faq.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,8 @@ Moltbook is a separate social network (created by Matt Schlicht) where AI agents
4141

4242
As of early July 2026, the latest stable release is **v2026.6.11** (published June 30, 2026), with **v2026.7.1** available as beta pre-releases. OpenClaw uses calendar versioning: `vYYYY.M.PATCH`, where the patch number is a sequential release counter within the month — not a calendar day.
4343

44+
Note: some users report a regression in v2026.6.11 where [tools return empty output after the first call in a turn](/reference/troubleshooting#empty-tool-output-after-first-call-v2026611) (upstream issue #98528).
45+
4446
---
4547

4648
## Security

‎docs/reference/gateway-api.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -198,6 +198,15 @@ const ws = new WebSocket('ws://localhost:18789?token=your-auth-token');
198198
**The lack of default authentication was the root cause of CVE-2026-25253.** Enable auth if multiple users share the machine.
199199
:::
200200

201+
## Protocol Versioning
202+
203+
The Gateway wire protocol is currently **version 4** (`PROTOCOL_VERSION: 4`), and general clients, operators, and UI connections must speak v4 (`MIN_CLIENT_PROTOCOL_VERSION: 4`). Since July 6, 2026 (PR #101109), there is an N-1 compatibility window for infrastructure connections: **nodes and probes at protocol v3 remain manageable** during rolling upgrades (`MIN_NODE_PROTOCOL_VERSION: 3`).
204+
205+
Recent Gateway-facing changes:
206+
207+
- **v2026.6.11** — plugin-registered Gateway methods now resolve through the live registry, so they work via `openclaw gateway call` instead of failing with `unknown method` (PR #94154)
208+
- **v2026.7.1 (beta)** — new `openclaw attach` command launches an external harness against an existing Gateway session, for resuming and inspecting interactive Codex-style workflows (#96454)
209+
201210
## See Also
202211

203212
- [The Gateway](/architecture/gateway) — Architecture details

‎docs/reference/troubleshooting.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -898,6 +898,10 @@ echo "nameserver 8.8.8.8" | sudo tee /etc/resolv.conf
898898

899899
## Post-Upgrade Issues
900900

901+
### Empty Tool Output After First Call (v2026.6.11)
902+
903+
Users report that on **v2026.6.11**, tools (`exec`, `web_fetch`, `web_search`) can return empty output after the first call in a turn. This is tracked upstream as [issue #98528](https://github.com/openclaw/openclaw/issues/98528) but is not acknowledged in the release notes, and the v2026.7.1 betas do not explicitly claim a fix. If you hit this, check the issue for current status — workarounds are staying on v2026.6.10 or trying the v2026.7.1 beta.
904+
901905
### Config Wiped After Upgrade
902906

903907
**Known issue in some v2026.5.x releases.** Always backup before upgrading:

‎docs/security/known-vulnerabilities.md‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -87,10 +87,11 @@ The full batch covers MCP loopback privilege exposure, plugin-install persistenc
8787

8888
### v2026.6.11 Security Hardening
8989

90-
The v2026.6.11 release (June 30, 2026) added two further security fixes:
90+
The v2026.6.11 release (June 30, 2026) added further security fixes:
9191

9292
- **Control UI DOMPurify update** ([GHSA-cmwh-pvxp-8882](https://github.com/advisories/GHSA-cmwh-pvxp-8882)) — the bundled sanitizer was updated to a patched DOMPurify release, mitigating `ALLOWED_ATTR` pollution via `setConfig()` (PR #95691)
9393
- **Lookalike package-source rejection** — trusted OpenClaw package sources now reject lookalike sibling paths (e.g., trusting `/artifactory/openclaw` no longer admits `/artifactory/openclaw-malicious`)
94+
- **ClawHub client DoS hardening** — oversized or stalled marketplace responses during skill discovery and install checks are now terminated before exhausting memory (PR #95226)
9495

9596
### Mitigation
9697

@@ -261,7 +262,7 @@ ClawHub was **open by default** — the only requirement to publish was a GitHub
261262

262263
1. **VirusTotal integration** (v2026.2.6+) — SHA-256 hashing checked on upload, Code Insight (Gemini-powered) analyzes full packages
263264
2. **Daily re-scanning** — Active skills re-scanned to detect skills that become malicious after initial upload
264-
3. **Community reporting** — Skills with 3+ unique reports are auto-hidden
265+
3. **Community reporting** — Skills are auto-hidden after 4 unique abuse reports (originally 3)
265266
4. **Built-in code safety scanner** — Static analysis for suspicious patterns
266267
5. **Verdicts system** — Benign (auto-approved), Suspicious (warning shown), Malicious (immediately blocked)
267268

@@ -406,7 +407,9 @@ When these findings were reported to creator Peter Steinberger, his response was
406407
| Feb 9 | Follow-up: 135,000+ exposed instances, 42,665 on Shodan | **Critical** |
407408
| Feb 9 | JFrog: 93.4% of exposed instances have auth bypass | **Critical** |
408409
| Feb 9 | Gartner: "Unacceptable cybersecurity risk" published | — |
410+
| Jun 1 | NVIDIA SkillSpector partnership — AI-assisted skill screening added to ClawScan | Mitigation |
409411
| Jun 12 | v2026.6.6 released — security-hardening release (140+ PRs) | Mitigation |
412+
| Jun 23 | Unit 42: five malicious skills evaded ClawHub scanning (infostealers, scanner evasion via 22 MB padding, Solana front-running); all removed | **High** |
410413
| Jun 30 | ~45 security advisories batch-published (MCP loopback, plugin-install bypasses, model-override auth) — most patched in v2026.6.6–v2026.6.8 | **High** |
411414
| Jun 30 | v2026.6.11 released — DOMPurify fix (GHSA-cmwh-pvxp-8882), lookalike package-source rejection | Mitigation |
412415

0 commit comments

Comments
 (0)