For people who
run agents.

Three places. Choose an agent. Read what changed. Check the evidence behind a skill or MCP server. The rest of the site supports those three jobs.

Registry stats loading…

Every report answers

1

What actually changed?

We separate release-note language from the behavior, policy, price, limit, or compatibility change that matters in practice.

2

What could it cost or break?

We look for pricing changes, migration risk, reliability regressions, security exposure, and hidden operational limits before recommending an update.

3

What should you do next?

Each report ends with a practical verdict: update, wait, test first, pin a version, change configuration, or ignore the announcement.

Latest intelligence2026-10-04

OpenClaw Security Advisories: 10 New CVEs Published Sep 11, 2026 — Two Are High-Severity (Exec Approvals Outliving the Reviewed Working Directory, and WhatsApp Login Tool Reaching Non-Owner Turns); Patched in 2026.8.1+

The openclaw/openclaw GitHub security advisories page was refreshed in the last 24 hours (the source-watcher fired at 2026-10-04 09:11 UTC) and now lists 10 new advisories, all dated 2026-09-11, replacing the prior baseline of 10 advisories all dated 2026-06-30. Two are High-severity: GHSA-3mq7-q27j-mq7q (Exec approvals could outlive their reviewed working directory) and GHSA-9m4p-cqp4-jppq (WhatsApp login tool could reach non-owner turns). The other eight are Moderate, covering Prometheus diagnostics, Discord asset uploads, iOS deep-link logs, browser relay capacity, OpenAI-compatible transport credential leakage, file-transfer approval widening, Slack file download authorization, and Unicode workspace-root fallback. All ten are patched in 2026.8.1+, so the current 2026.8.35 LTS, 2026.9.4, 2026.9.7, and 2026.9.8 lines are all on the fix. The bottleneck is version hygiene on pinned installs, not awareness. This report is a documentation comparison; no firsthand install, exploit, or upgrade was run.

What this site is

We have been writing about agents. This is the map, so you do not have to guess which page does which job.

How the change log is written

We do not rewrite launch posts. We connect primary sources, reproducible tests, scanner evidence, Registry records, and technical guides to the decision in front of you.

Primary sources before commentary

Pricing, policy, security, compatibility, and incident claims start with official documentation, repositories, advisories, or status pages. Community reports are labeled as experience, not proof.

Tests are reproducible or clearly untested

Field reports name the version, environment, method, inputs, and limitations. If we only compared documentation, we say so.

Registry and scanners support the story

The skills and MCP Registry remains free. Its source links, scan states, provenance, and explicit evidence gaps help test whether an ecosystem claim survives contact with real artifacts.

Blueprints and guides remain practical

Durable technical guides and inspectable workflow manifests turn a news event into implementation work you can adapt and validate in your own environment.

Start with an agent

See the full list →
Coverage

The list is short on purpose.

A landing page that says "AI agent" is not a listing. The directory covers coding, ops, voice, research, and go-to-market runtimes. Autonomy is a tested facet, not a slogan.

// CHANGES_WITH_CONSEQUENCES

Follow the changes that matter.

Weekday impact reports, a weekly Before You Update brief, and tested comparisons when the evidence supports them. No quota filler.

The change log is the news. Agent dossiers are the catalog.

Open the change log

Choose an agent. Then follow what changes.

Live registryRegistry loading…Snapshot date unavailable