You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
4. **Hold period** — New releases may be held from install surfaces until review completes; scan-held/blocked releases stay visible to their owners but are hidden from public catalogs
335
+
5. **Available** — Once cleared, the skill appears in search and can be installed
335
336
336
337
If validation fails, nothing is published and you get an error explaining why.
100% of confirmed malicious skills contained malicious code, while 91% also employed prompt injection techniques.
384
385
386
+
### Unit 42 Findings (June 2026)
387
+
388
+
On June 23, 2026, Palo Alto Networks' Unit 42 published research identifying **five malicious skills that evaded ClawHub's scanning** during their February–May 2026 analysis:
389
+
390
+
- **Two macOS infostealers** with command-and-control connectivity (linked to cluw and Atomic macOS Stealer)
391
+
- **`omnicogg`** — a scanner-evasion skill using 22 MB of file padding to exceed content-analysis size limits
- **`letssendit`** — an agentic Solana front-running skill
394
+
395
+
OpenClaw banned the publisher accounts and deleted all five skills. The takeaway: scanning keeps improving (see below), but evasion keeps pace — always review skill source before installing.
396
+
385
397
### Broader Quality Issues
386
398
387
399
Snyk's ToxicSkills audit found problems beyond just intentionally malicious skills:
@@ -393,9 +405,13 @@ Snyk's ToxicSkills audit found problems beyond just intentionally malicious skil
393
405
394
406
**Automated scanning:**
395
407
- **VirusTotal integration** (v2026.2.6+) — All skills scanned on upload, periodic re-scanning
408
+
- **NVIDIA SkillSpector** (June 1, 2026 partnership) — Static checks plus AI-assisted semantic analysis in the ClawScan pipeline, producing Clean/Suspicious/Malicious verdicts, along with Skill Cards for provenance
409
+
- **Staged publishing** (July 2026+) — Publishes held behind prepublication checks before finalization
396
410
- **Code pattern analysis** — Checks declared frontmatter vs actual behavior, flags mismatches
Copy file name to clipboardExpand all lines: docs/guides/webclaw.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -10,7 +10,7 @@ keywords: [openclaw, webclaw, web client, browser frontend, web ui, react fronte
10
10
[WebClaw](https://github.com/ibelick/webclaw) is a community-built, browser-based chat interface for OpenClaw. It connects to your Gateway over WebSockets and provides a clean, modern UI for interacting with your agent from any device with a browser.
11
11
12
12
:::info
13
-
WebClaw is currently in **beta** (637 stars, 5 contributors). It is a third-party project and not maintained by the OpenClaw team. The repository was last updated March 17, 2026.
13
+
WebClaw is currently in **beta** (~639 stars, 5 contributors). It is a third-party project and not maintained by the OpenClaw team. As of July 2026 it has had no commits, tags, or releases since March 17, 2026 — development appears stalled (the npm package remains at v0.1.1 from February 2026). Consider [PinchChat](#pinchchat-alternative-frontend) if you need an actively maintained frontend.
Copy file name to clipboardExpand all lines: docs/reference/faq.md
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -41,6 +41,8 @@ Moltbook is a separate social network (created by Matt Schlicht) where AI agents
41
41
42
42
As of early July 2026, the latest stable release is **v2026.6.11** (published June 30, 2026), with **v2026.7.1** available as beta pre-releases. OpenClaw uses calendar versioning: `vYYYY.M.PATCH`, where the patch number is a sequential release counter within the month — not a calendar day.
43
43
44
+
Note: some users report a regression in v2026.6.11 where [tools return empty output after the first call in a turn](/reference/troubleshooting#empty-tool-output-after-first-call-v2026611) (upstream issue #98528).
Copy file name to clipboardExpand all lines: docs/reference/gateway-api.md
+9Lines changed: 9 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -198,6 +198,15 @@ const ws = new WebSocket('ws://localhost:18789?token=your-auth-token');
198
198
**The lack of default authentication was the root cause of CVE-2026-25253.** Enable auth if multiple users share the machine.
199
199
:::
200
200
201
+
## Protocol Versioning
202
+
203
+
The Gateway wire protocol is currently **version 4** (`PROTOCOL_VERSION: 4`), and general clients, operators, and UI connections must speak v4 (`MIN_CLIENT_PROTOCOL_VERSION: 4`). Since July 6, 2026 (PR #101109), there is an N-1 compatibility window for infrastructure connections: **nodes and probes at protocol v3 remain manageable** during rolling upgrades (`MIN_NODE_PROTOCOL_VERSION: 3`).
204
+
205
+
Recent Gateway-facing changes:
206
+
207
+
-**v2026.6.11** — plugin-registered Gateway methods now resolve through the live registry, so they work via `openclaw gateway call` instead of failing with `unknown method` (PR #94154)
208
+
-**v2026.7.1 (beta)** — new `openclaw attach` command launches an external harness against an existing Gateway session, for resuming and inspecting interactive Codex-style workflows (#96454)
### Empty Tool Output After First Call (v2026.6.11)
902
+
903
+
Users report that on **v2026.6.11**, tools (`exec`, `web_fetch`, `web_search`) can return empty output after the first call in a turn. This is tracked upstream as [issue #98528](https://github.com/openclaw/openclaw/issues/98528) but is not acknowledged in the release notes, and the v2026.7.1 betas do not explicitly claim a fix. If you hit this, check the issue for current status — workarounds are staying on v2026.6.10 or trying the v2026.7.1 beta.
904
+
901
905
### Config Wiped After Upgrade
902
906
903
907
**Known issue in some v2026.5.x releases.** Always backup before upgrading:
Copy file name to clipboardExpand all lines: docs/security/known-vulnerabilities.md
+5-2Lines changed: 5 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -87,10 +87,11 @@ The full batch covers MCP loopback privilege exposure, plugin-install persistenc
87
87
88
88
### v2026.6.11 Security Hardening
89
89
90
-
The v2026.6.11 release (June 30, 2026) added two further security fixes:
90
+
The v2026.6.11 release (June 30, 2026) added further security fixes:
91
91
92
92
-**Control UI DOMPurify update** ([GHSA-cmwh-pvxp-8882](https://github.com/advisories/GHSA-cmwh-pvxp-8882)) — the bundled sanitizer was updated to a patched DOMPurify release, mitigating `ALLOWED_ATTR` pollution via `setConfig()` (PR #95691)
93
93
-**Lookalike package-source rejection** — trusted OpenClaw package sources now reject lookalike sibling paths (e.g., trusting `/artifactory/openclaw` no longer admits `/artifactory/openclaw-malicious`)
94
+
-**ClawHub client DoS hardening** — oversized or stalled marketplace responses during skill discovery and install checks are now terminated before exhausting memory (PR #95226)
94
95
95
96
### Mitigation
96
97
@@ -261,7 +262,7 @@ ClawHub was **open by default** — the only requirement to publish was a GitHub
261
262
262
263
1.**VirusTotal integration** (v2026.2.6+) — SHA-256 hashing checked on upload, Code Insight (Gemini-powered) analyzes full packages
263
264
2.**Daily re-scanning** — Active skills re-scanned to detect skills that become malicious after initial upload
264
-
3.**Community reporting** — Skills with 3+ unique reports are auto-hidden
265
+
3.**Community reporting** — Skills are auto-hidden after 4 unique abuse reports (originally 3)
265
266
4.**Built-in code safety scanner** — Static analysis for suspicious patterns
@@ -406,7 +407,9 @@ When these findings were reported to creator Peter Steinberger, his response was
406
407
| Feb 9 | Follow-up: 135,000+ exposed instances, 42,665 on Shodan |**Critical**|
407
408
| Feb 9 | JFrog: 93.4% of exposed instances have auth bypass |**Critical**|
408
409
| Feb 9 | Gartner: "Unacceptable cybersecurity risk" published | — |
410
+
| Jun 1 | NVIDIA SkillSpector partnership — AI-assisted skill screening added to ClawScan | Mitigation |
409
411
| Jun 12 | v2026.6.6 released — security-hardening release (140+ PRs) | Mitigation |
412
+
| Jun 23 | Unit 42: five malicious skills evaded ClawHub scanning (infostealers, scanner evasion via 22 MB padding, Solana front-running); all removed |**High**|
410
413
| Jun 30 |~45 security advisories batch-published (MCP loopback, plugin-install bypasses, model-override auth) — most patched in v2026.6.6–v2026.6.8 |**High**|
411
414
| Jun 30 | v2026.6.11 released — DOMPurify fix (GHSA-cmwh-pvxp-8882), lookalike package-source rejection | Mitigation |
0 commit comments