惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
J
Java Code Geeks
量子位
腾讯CDC
C
Check Point Blog
小众软件
小众软件
IT之家
IT之家
I
InfoQ
Hugging Face - Blog
Hugging Face - Blog
Stack Overflow Blog
Stack Overflow Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
GbyAI
GbyAI
Apple Machine Learning Research
Apple Machine Learning Research
大猫的无限游戏
大猫的无限游戏
博客园_首页
S
SegmentFault 最新的问题
The Cloudflare Blog
阮一峰的网络日志
阮一峰的网络日志
aimingoo的专栏
aimingoo的专栏
P
Proofpoint News Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Google DeepMind News
Google DeepMind News
T
Tailwind CSS Blog
Martin Fowler
Martin Fowler

OpenClaw Blog

OpenClaw improves user onboarding with a new installer on macOS, plus easier local model setup for Windows NVIDIA RTX PCs - OpenClaw Blog OpenClaw 2.0, Accidentally - OpenClaw Blog On the Road to LTS: Extended-Stable Releases and the Maturity Scorecard - OpenClaw Blog Introducing the OpenClaw Foundation - OpenClaw Blog Skill Workshop: Turn Agent Work Into Reusable Skills OpenClaw Collaborates with NVIDIA for Stronger Agent Skill Security Auto Mode Is the Safer Way to Let Agents Run Commands - OpenClaw Blog Safer Than YOLO: Auto Mode for Exec Approvals OpenClaw Is Getting Faster, Smaller, and Easier to Trust Where OpenClaw Security Is Heading OpenAI Models in OpenClaw, Done Right OpenClaw Had a Rough Week How OpenClaw Got Safer in Public OpenClaw Partners with VirusTotal for Skill Security Introducing OpenClaw
Where to find OpenClaw security updates - OpenClaw Blog
OpenClaw Security Team · 2026-09-16 · via OpenClaw Blog
All posts

Where to find OpenClaw security status, advisories, ongoing work, research, and vulnerability reporting guidance.

As an open-source project, securing OpenClaw is ongoing work.

A trusted group of maintainers, including security engineers from NVIDIA and Tencent, volunteer their time to review reports, investigate issues, ship fixes, and strengthen the project as it evolves. A lot of this work happens behind the scenes, and we want to make more of it visible and easier to understand.

This week, we rolled out a security page for all to see where OpenClaw security stands, what we’re working on, what we’ve fixed, and how to reach us when something needs our attention.

The page brings together information that previously lived across GitHub, documentation, blog posts, and individual advisories. It includes:

  • Current security status and advisories, including whether there are any active security bulletins.
  • The numbers behind vulnerability reports. Since January, 722 fixes have been published. Fourteen reports resulted in confirmed critical vulnerabilities; all of them had been fixed and disclosed.
  • Where fixes are happening, from gateway authentication and scopes to sandboxing, approvals, connectors, filesystem handling, plugins, skills, and network access.
  • Ongoing security work, including ClawHub skill scanning, install blocking for malicious or quarantined skills, safer filesystem access, command-chain checks, network egress controls, and regression testing based on previously patched advisories.
  • A clear vulnerability reporting process, including what makes a useful report, what happens after one is submitted, and what falls outside OpenClaw’s security model.
  • Security research and write-ups, from both OpenClaw contributors and outside researchers.

We’re also making more of our underlying security work available. One recent example: OpenClaw has published an open dataset containing more than 67,000 ClawHub skill scans, alongside research into how different security scanners evaluate the same skills.

Our work is never done. OpenClaw connects models to tools, files, browsers, services, and other systems, and those capabilities create security boundaries that keep evolving with the project.

As a reminder, if you find a potential vulnerability, please report it privately to give our maintainers time to investigate and ship a fix before technical details are public.

Explore more at openclaw.ai/security. 🦞