OpenClaw Hardens Vault Setup Plans Against Symlink and File-Clobber Attacks
A security fix on OpenClaw main makes Vault and 1Password secret-plan writes exclusive and owner-only. Operators should protect old plans and verify the containing release.
Security desk
A security fix on OpenClaw main makes Vault and 1Password secret-plan writes exclusive and owner-only. Operators should protect old plans and verify the containing release.
A merged main-branch fix makes normal routed agent replies pass through plugin rewrite and cancellation hooks before channel delivery.
Four merged main-branch changes tighten read-only diagnostics, verifier quarantine, schema upgrades and filesystem durability around OpenClaw state.
Claude CLI sessions under restrictive policy can now request human approval for native and extension tools instead of silently denying them, with Bash and timeout paths kept fail-closed.
Main-branch fixes address Matrix key migration, Control UI pairing, concurrent MCP config loss, large-inode startup failures and macOS certificate trust.
A merged OpenClaw fix preserves creator-authorized Cron tool caps across scheduled, CLI and cloud-worker execution without letting the cap override current safety policy.
OpenClaw has tightened reusable command approvals and Discord sender-scoped history on main. Current npm packages predate both fixes.
OpenClaw can be safe for one trusted operator, but not as a hostile shared tenant. Understand the real risks, controls and launch checklist.
From late January through February, OpenClaw moved browser control behind the Gateway and tightened bridge, relay, network and token boundaries.
OpenClaw versions before 2026.5.28 could let workspace dotenv files override provider credentials. Here is the real exposure and operator response.
OpenClaw is a self-hosted AI gateway that connects models, messaging channels and tools. Learn how it works, what stays local and who it suits.