Three places. Choose an agent. Read what changed. Check the evidence behind a skill or MCP server. The rest of the site supports those three jobs.
Registry stats loading…
We separate release-note language from the behavior, policy, price, limit, or compatibility change that matters in practice.
We look for pricing changes, migration risk, reliability regressions, security exposure, and hidden operational limits before recommending an update.
Each report ends with a practical verdict: update, wait, test first, pin a version, change configuration, or ignore the announcement.
The openclaw/openclaw GitHub security advisories page was refreshed in the last 24 hours (the source-watcher fired at 2026-10-04 09:11 UTC) and now lists 10 new advisories, all dated 2026-09-11, replacing the prior baseline of 10 advisories all dated 2026-06-30. Two are High-severity: GHSA-3mq7-q27j-mq7q (Exec approvals could outlive their reviewed working directory) and GHSA-9m4p-cqp4-jppq (WhatsApp login tool could reach non-owner turns). The other eight are Moderate, covering Prometheus diagnostics, Discord asset uploads, iOS deep-link logs, browser relay capacity, OpenAI-compatible transport credential leakage, file-transfer approval widening, Slack file download authorization, and Unicode workspace-root fallback. All ten are patched in 2026.8.1+, so the current 2026.8.35 LTS, 2026.9.4, 2026.9.7, and 2026.9.8 lines are all on the fix. The bottleneck is version hygiene on pinned installs, not awareness. This report is a documentation comparison; no firsthand install, exploit, or upgrade was run.
We have been writing about agents. This is the map, so you do not have to guess which page does which job.
A short list of agents people actually run. Each dossier says when to pick it, when to skip it, and what it writes. Not a tools dump.
Releases, prices, limits, outages, and compatibility. Each report should say what changed, what could break, and what to do next.
Skills and MCP records, with scan states and gaps. This is not a product catalog and not a safety certificate.
We do not rewrite launch posts. We connect primary sources, reproducible tests, scanner evidence, Registry records, and technical guides to the decision in front of you.
Pricing, policy, security, compatibility, and incident claims start with official documentation, repositories, advisories, or status pages. Community reports are labeled as experience, not proof.
Field reports name the version, environment, method, inputs, and limitations. If we only compared documentation, we say so.
The skills and MCP Registry remains free. Its source links, scan states, provenance, and explicit evidence gaps help test whether an ecosystem claim survives contact with real artifacts.
Durable technical guides and inspectable workflow manifests turn a news event into implementation work you can adapt and validate in your own environment.
Anthropic's coding agent CLI. Reads project instructions, calls tools, and stays human-gated per session.
OpenAI's coding agent CLI. Tool-using and session-gated. Not the hosted Agents API.
Self-hosted agent gateway with channels, cron, and write-tools. Failure has an operator.
A landing page that says "AI agent" is not a listing. The directory covers coding, ops, voice, research, and go-to-market runtimes. Autonomy is a tested facet, not a slogan.
Weekday impact reports, a weekly Before You Update brief, and tested comparisons when the evidence supports them. No quota filler.
The change log is the news. Agent dossiers are the catalog.
Open the change log