惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
N
Netflix TechBlog - Medium
宝玉的分享
宝玉的分享
Google DeepMind News
Google DeepMind News
腾讯CDC
G
Google Developers Blog
Martin Fowler
Martin Fowler
Microsoft Security Blog
Microsoft Security Blog
Recent Announcements
Recent Announcements
爱范儿
爱范儿
Engineering at Meta
Engineering at Meta
Microsoft Azure Blog
Microsoft Azure Blog
A
About on SuperTechFans
aimingoo的专栏
aimingoo的专栏
有赞技术团队
有赞技术团队
Jina AI
Jina AI
人人都是产品经理
人人都是产品经理
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
M
MIT News - Artificial intelligence
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
美团技术团队
WordPress大学
WordPress大学
阮一峰的网络日志
阮一峰的网络日志

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
docs: document trusted skill symlink targets · openclaw/o...
steipete · 2026-05-09 · via Recent Commits to openclaw:main
Original file line numberDiff line numberDiff line change

@@ -62,6 +62,53 @@ openclaw config get meta.lastTouchedVersion

6262

For intentional downgrade or emergency recovery only, set `OPENCLAW_ALLOW_OLDER_BINARY_DESTRUCTIVE_ACTIONS=1` for the single command. Leave it unset for normal operation.

6363

</Warning>

6464
65+

## Skill symlink skipped as path escape

66+
67+

Use this when logs include:

68+
69+

```text

70+

Skipping escaped skill path outside its configured root: ... reason=symlink-escape

71+

```

72+
73+

OpenClaw treats every skill root as a containment boundary. A symlink under

74+

`~/.agents/skills`, `<workspace>/.agents/skills`, `<workspace>/skills`, or

75+

`~/.openclaw/skills` is skipped when its real target resolves outside that root

76+

unless the target is explicitly trusted.

77+
78+

Inspect the link:

79+
80+

```bash

81+

ls -l ~/.agents/skills/<name>

82+

realpath ~/.agents/skills/<name>

83+

openclaw config get skills.load

84+

```

85+
86+

If the target is intentional, configure both the direct skill root and the

87+

allowed symlink target:

88+
89+

```json5

90+

{

91+

skills: {

92+

load: {

93+

extraDirs: ["~/Projects/manager/skills"],

94+

allowSymlinkTargets: ["~/Projects/manager/skills"],

95+

},

96+

},

97+

}

98+

```

99+
100+

Then start a new session or wait for the skills watcher to refresh. Restart the

101+

gateway if the running process predates the config change.

102+
103+

Do not use broad targets such as `~`, `/`, or a whole synced project folder.

104+

Keep `allowSymlinkTargets` scoped to the real skill root that contains trusted

105+

`SKILL.md` directories.

106+
107+

Related:

108+
109+

- [Skills config](/tools/skills-config#symlinked-sibling-repos)

110+

- [Configuration examples](/gateway/configuration-examples#symlinked-sibling-skill-repo)

111+
65112

## Anthropic 429 extra usage required for long context

66113
67114

Use this when logs/errors include: `HTTP 429: rate_limit_error: Extra usage is required for long context requests`.