# OpenClaw

OpenClaw is an open-source AI assistant that runs on your machine and offers apps, documentation, and installation tools.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Grok Bot vs. OpenClaw: How I replaced my entire agent stack

DevFeed: [Grok Bot vs. OpenClaw: How I replaced my entire agent stack](<https://devfeed.tech/articles/grok-bot-vs-openclaw-how-i-replaced-my-entire-agent-stack-40016.md>)

Original publisher: [Read original article](<https://www.lennysnewsletter.com/p/grok-bot-vs-openclaw-how-i-replaced>)

Author: Claire Vo

Published: 2026-09-02T12:03:39Z

Content type: comparison

Language: en

Sources: [Lenny's Newsletter](<https://devfeed.tech/sources/lenny-s-newsletter.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [multi-agent](<https://devfeed.tech/topics/multi-agent.md>), [Bot](<https://devfeed.tech/topics/bot.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [soc 2 compliance](<https://devfeed.tech/topics/soc-2-compliance.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Support](<https://devfeed.tech/topics/support.md>), [Slack](<https://devfeed.tech/topics/slack.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [bots](<https://devfeed.tech/tags/bots.md>), [helpdesk](<https://devfeed.tech/tags/helpdesk.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [multi-agent](<https://devfeed.tech/tags/multi-agent.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [rbac](<https://devfeed.tech/tags/rbac.md>), [slack](<https://devfeed.tech/tags/slack.md>), [soc-2-compliance](<https://devfeed.tech/tags/soc-2-compliance.md>)

### AI overview

A podcast episode compares Grok Bot with OpenClaw and explains why the host migrated a multi-agent setup to Grok Bot. It covers bots for inboxes, Slack, PR management, SOC 2 monitoring, customer support, family tasks, and personal activities, along with the migration process.

### Source excerpt

Watch now | 🎙 I've been running Grok Bot for several weeks, and I've killed every OpenClaw I had. Here are the nine bots doing real work across my inbox, my kids' school pickups, my PR queue, and my wardrobe

## How to build a Company Operating System with Hermes and OpenClaw

DevFeed: [How to build a Company Operating System with Hermes and OpenClaw](<https://devfeed.tech/articles/how-to-build-a-company-operating-system-with-hermes-and-openclaw-34973.md>)

Original publisher: [Read original article](<https://www.news.aakashg.com/p/company-os-hermes-openclaw>)

Author: Aakash Gupta

Published: 2026-08-28T22:38:13Z

Content type: tutorial

Language: en

Sources: [Product Growth](<https://devfeed.tech/sources/product-growth.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [build](<https://devfeed.tech/tags/build.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>)

### AI overview

This podcast episode explains how to build a Company OS using Hermes and OpenClaw. It covers an open-source agent skeleton, Slack and Telegram integration, continuous operation, automated skill generation, persistent identity, memory layers, and measuring product context coverage.

### Source excerpt

Claude Code is just the start of what a Company OS can do. Here's how to take it to the next level.

## OpenClaw went viral. Meet the maintainers building and securing it.

DevFeed: [OpenClaw went viral. Meet the maintainers building and securing it.](<https://devfeed.tech/articles/openclaw-went-viral-meet-the-maintainers-building-and-securing-it-84.md>)

Original publisher: [Read original article](<https://github.blog/open-source/maintainers/openclaw-went-viral-meet-the-maintainers-building-and-securing-it/>)

Author: Gregg Cochran

Published: 2026-08-27T16:00:00Z

Content type: article

Language: en

Sources: [GitHub Engineering](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Code review](<https://devfeed.tech/topics/code-review.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [contributors](<https://devfeed.tech/tags/contributors.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [github](<https://devfeed.tech/tags/github.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [review](<https://devfeed.tech/tags/review.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

OpenClaw maintainers discuss the project's rapid growth, the resulting flood of pull requests, contributor trust, code review, software supply chain risks, and security. They describe welcoming contributions from first-time contributors, non-developers, and people using AI agents while refining promising changes.

### Source excerpt

OpenClaw is the fastest-growing project in GitHub history. Peter Steinberger and several maintainers share what they learned in the project's first six months. The post OpenClaw went viral. Meet the maintainers building and securing it. appeared first on The GitHub Blog.

## 🎙 How I AI: Grok Bot + Grok 4.6--what's great (and what's still hype) & Lessons from spending $20,000 on Devin in one month

DevFeed: [🎙 How I AI: Grok Bot + Grok 4.6--what's great (and what's still hype) & Lessons from spending $20,000 on Devin in one month](<https://devfeed.tech/articles/how-i-ai-grok-bot-grok-4-6-what-s-great-and-what-s-still-hype-lessons-from-spending-20-000-on-devin-in-one-month-40019.md>)

Original publisher: [Read original article](<https://www.lennysnewsletter.com/p/how-i-ai-grok-bot-grok-46whats-great>)

Author: Lenny Rachitsky

Published: 2026-08-24T15:02:23Z

Content type: opinion

Language: en

Sources: [Lenny's Newsletter](<https://devfeed.tech/sources/lenny-s-newsletter.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Bot](<https://devfeed.tech/topics/bot.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Frontier Model](<https://devfeed.tech/topics/frontier-model.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [email](<https://devfeed.tech/topics/email.md>), [Slack](<https://devfeed.tech/topics/slack.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [claude](<https://devfeed.tech/tags/claude.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [frontier-model](<https://devfeed.tech/tags/frontier-model.md>), [github](<https://devfeed.tech/tags/github.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [podcast](<https://devfeed.tech/tags/podcast.md>)

### AI overview

This solo podcast episode evaluates Grok Bot, Cursor Origin, and Grok 4.6. It finds Grok Bot's multi-account connectors particularly useful, describes its simplicity as both a strength and a limitation, considers Cursor Origin promising but not yet a strong replacement for GitHub, and reports that Grok 4.6 performed competitively in the presenter's blind evaluations. The episode also favors Claude Sonnet 5 for concise, responsive agent conversations.

### Source excerpt

Your weekly listens from How I AI, part of the Lenny's Podcast Network

## I spent $20,000 on Devin in a month. Here's what I learned | Ryan Carson (solo founder)

DevFeed: [I spent $20,000 on Devin in a month. Here's what I learned | Ryan Carson (solo founder)](<https://devfeed.tech/articles/i-spent-20-000-on-devin-in-a-month-here-s-what-i-learned-ryan-carson-solo-founder-40026.md>)

Original publisher: [Read original article](<https://www.lennysnewsletter.com/p/i-spent-20000-on-devin-in-a-month>)

Author: Claire Vo

Published: 2026-08-24T12:04:02Z

Content type: opinion

Language: en

Sources: [Lenny's Newsletter](<https://devfeed.tech/sources/lenny-s-newsletter.md>)

Topics: [coding](<https://devfeed.tech/topics/coding.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [codex](<https://devfeed.tech/topics/codex.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [building](<https://devfeed.tech/tags/building.md>), [claude](<https://devfeed.tech/tags/claude.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [codex](<https://devfeed.tech/tags/codex.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>)

### AI overview

A podcast episode featuring solo founder Ryan Carson discusses how he uses concurrent Devin agents and other AI tools for engineering, customer success, operations, and product work. The episode also covers monitoring accounts, managing pull-request workflows, choosing between Codex, Devin, and Claude Code, and using Claude Design with Codex.

### Source excerpt

Watch now | 🎙 Solo founder Ryan Carson runs 15 concurrent Devin agents to handle engineering, customer success, and investor updates, and he uses a handwritten list to keep it all straight

## How Ora benchmarks every major AI agent on Vercel

DevFeed: [How Ora benchmarks every major AI agent on Vercel](<https://devfeed.tech/articles/how-ora-benchmarks-every-major-ai-agent-on-vercel-745.md>)

Original publisher: [Read original article](<https://vercel.com/blog/how-ora-benchmarks-every-major-ai-agent-on-vercel>)

Author: Kevin Sundstrom

Published: 2026-08-21T21:00:00Z

Content type: article

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Vercel](<https://devfeed.tech/topics/vercel.md>), [agent observability](<https://devfeed.tech/topics/agent-observability.md>), [Traces](<https://devfeed.tech/topics/traces.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [Latency](<https://devfeed.tech/topics/latency.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [backends](<https://devfeed.tech/topics/backends.md>), [Front end](<https://devfeed.tech/topics/frontend.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [benchmarks](<https://devfeed.tech/tags/benchmarks.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [latency](<https://devfeed.tech/tags/latency.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [software](<https://devfeed.tech/tags/software.md>), [tools](<https://devfeed.tech/tags/tools.md>), [traces](<https://devfeed.tech/tags/traces.md>), [vercel](<https://devfeed.tech/tags/vercel.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Ora benchmarks major AI agents by running them against live customer websites and recording the cost, latency, steps, and traces required to complete workflows. Built on Vercel, the platform provides the front end, back end, and agent runtime through one deployment path.

### Source excerpt

Ora on Vercel Front end, back end, and agent runtime on one platform Every major agent tested side by side on live sites Hundreds of commits a day from a 16-person engineering team Ora sends agents onto live websites with instructions to sign up for a product, integrate with it, and pay for it. Agents often fail, and by Ora's estimate, 99% of the web isn't agent-ready. The platform shows customers where and why agents fail, and what to change. Assaf Elovic, co-founder of Ora, spent years helping agents discover the web. His previous company, Tavily, built a web search engine for AI agents and was acquired by Nebius earlier this year. Search solved half the problem, but an agent that finds a product still has to actually use it. He and co-founder Liad Yosef started Ora to measure how ready the web is for agents, and to fix the parts that aren't. Today that means spawning agents against live customer sites from journey.ora.ai, where Ora runs a journey and records the cost, latency, and steps an agent needs to finish a task. The platform runs on Vercel, including the agent runtime. Benchmarking every major agent side by sideEvery harness expects its own infrastructure Agents decompose into two parts: a model, which does the reasoning, and a harness, the software that gives the model its tools and drives it from step to step. Ora's lineup covers the agents customers use most: Claude Code, ChatGPT, Gemini, Hermes, OpenClaw, and eve, Vercel's agent framework. Ora runs each agent on a customer's website and watches how it handles common workflows. No two harnesses want the same infrastructure. Each expects its own environment and exposes its steps differently, so Ora runs a separate runtime for every harness and traces every step. Ido Finder, who leads engineering at Ora, calls that side-by-side coverage one of the most valuable things ora brings to its customers. When an agent stalls in a signup flow, the customer sees which step and what it tried. Without the trace, the

## Meta offers retention equity grants as staff leave; article examines Grok Bot and OpenClaw

DevFeed: [Meta offers retention equity grants as staff leave; article examines Grok Bot and OpenClaw](<https://devfeed.tech/articles/the-pulse-meta-s-self-inflicted-resignation-wave-18183.md>)

Original publisher: [Read original article](<https://newsletter.pragmaticengineer.com/p/the-pulse-metas-self-inflicted-resignation>)

Author: Gergely Orosz

Published: 2026-08-14T16:55:55Z

Content type: article

Language: en

Sources: [The Pragmatic Engineer](<https://devfeed.tech/sources/the-pragmatic-engineer.md>)

Topics: [Meta](<https://devfeed.tech/topics/meta.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [meta](<https://devfeed.tech/tags/meta.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>)

### AI overview

The article discusses Meta offering more than $1 million in retention equity grants to employees who are leaving and considers whether Grok Bot could represent an "OpenClaw moment" for managed AI agents.

### Source excerpt

The social media giant is offering $1M+ retainer equity grants to staff who are leaving: and even this is not effective. Also: is Grok Bot the "OpenClaw moment" for managed AI agents?

## One audit trail for every coding agent, and what it proves

DevFeed: [One audit trail for every coding agent, and what it proves](<https://devfeed.tech/articles/one-audit-trail-for-every-coding-agent-and-what-it-proves-16003.md>)

Original publisher: [Read original article](<https://workos.com/blog/audit-trail-for-every-coding-agent>)

Author: WorkOS

Published: 2026-08-13T00:00:00Z

Content type: article

Language: en

Sources: [WorkOS Blog](<https://devfeed.tech/sources/workos-blog.md>)

Topics: [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [audit](<https://devfeed.tech/topics/audit.md>), [coding](<https://devfeed.tech/topics/coding.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [codex](<https://devfeed.tech/topics/codex.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [MCP](<https://devfeed.tech/topics/mcp.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [api](<https://devfeed.tech/tags/api.md>), [audit](<https://devfeed.tech/tags/audit.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [claude](<https://devfeed.tech/tags/claude.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [code](<https://devfeed.tech/tags/code.md>), [codex](<https://devfeed.tech/tags/codex.md>), [coding](<https://devfeed.tech/tags/coding.md>), [logging](<https://devfeed.tech/tags/logging.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [siem](<https://devfeed.tech/tags/siem.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [visibility](<https://devfeed.tech/tags/visibility.md>)

### AI overview

This article describes WorkOS audit logging for Claude Code, Codex, OpenClaw, and pi. Its shared plugin and harness capture agent session, prompt, and tool lifecycle events, resolve activity to people, and make events queryable through a console, Export API, SIEM streaming, and MCP.

### Source excerpt

We built audit logging for Claude Code, Codex, OpenClaw and pi with no API key on any laptop. Use it to get total visibility into your entire org's agentic activity.

## What is Openclaw?

DevFeed: [What is Openclaw?](<https://devfeed.tech/articles/what-is-openclaw-30883.md>)

Original publisher: [Read original article](<https://www.rogerperkin.co.uk/faq/what-is-openclaw/>)

Author: Roger Perkin

Published: 2026-07-24T13:32:05Z

Content type: article

Language: en

Sources: [Roger Perkin Network Automation Consultant](<https://devfeed.tech/sources/roger-perkin-network-automation-consultant.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Shell](<https://devfeed.tech/topics/shell.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Discord](<https://devfeed.tech/topics/discord.md>), [Slack](<https://devfeed.tech/topics/slack.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [discord](<https://devfeed.tech/tags/discord.md>), [faq](<https://devfeed.tech/tags/faq.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [shell](<https://devfeed.tech/tags/shell.md>), [slack](<https://devfeed.tech/tags/slack.md>)

### AI overview

OpenClaw is described as an autonomous, open-source AI agent that can run locally or on a cloud server. It operates in the background, reading files, executing shell commands, and taking actions across apps including WhatsApp, Discord, and Slack.

### Source excerpt

OpenClaw is an autonomous, open-source AI agent that runs locally on your machine or cloud server. Unlike traditional chatbots that only answer questions, it operates 24/7 in the background, reading files, executing shell commands, and taking proactive actions on your behalf across apps like WhatsApp, Discord, or Slack.

## Why the author replaced Hermes Agent and OpenClaw with a simpler personal AI assistant

DevFeed: [Why the author replaced Hermes Agent and OpenClaw with a simpler personal AI assistant](<https://devfeed.tech/articles/why-i-stopped-using-hermes-and-openclaw-and-what-i-built-instead-18328.md>)

Original publisher: [Read original article](<https://newsletter.aiengineer.co/p/why-i-stopped-using-hermes-and-openclaw>)

Author: Owain Lewis

Published: 2026-07-18T10:16:21Z

Content type: opinion

Language: en

Sources: [The AI Engineer](<https://devfeed.tech/sources/the-ai-engineer.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [Messaging](<https://devfeed.tech/topics/messaging.md>), [coding](<https://devfeed.tech/topics/coding.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [coding-agents](<https://devfeed.tech/tags/coding-agents.md>), [messaging](<https://devfeed.tech/tags/messaging.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [personal](<https://devfeed.tech/tags/personal.md>)

### AI overview

The author explains why Hermes Agent and OpenClaw became frustrating to use as a daily AI personal assistant, focusing on their complexity and overhyped features. The article describes the personal assistant pattern, messaging gateways, and the author's simpler solution built around organisational tasks and existing coding agents.

### Source excerpt

How I built my own personal AI Chief of Staff without all the complexity.

## Security Week 2627: поддельные инструменты ИИ как приманка для малого бизнеса

DevFeed: [Security Week 2627: поддельные инструменты ИИ как приманка для малого бизнеса](<https://devfeed.tech/articles/security-week-2627-23078.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/kaspersky/articles/1053146/>)

Author: Kaspersky\_Lab ("Лаборатория Касперского")

Published: 2026-06-30T12:05:19Z

Content type: news

Language: ru

Sources: ["Лаборатория Касперского" RU](<https://devfeed.tech/sources/ru-2.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [claude](<https://devfeed.tech/tags/claude.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [smb](<https://devfeed.tech/tags/smb.md>), [tag-9fe8963de219](<https://devfeed.tech/tags/tag-9fe8963de219.md>), [tag-cc2a6346d835](<https://devfeed.tech/tags/tag-cc2a6346d835.md>)

### AI overview

The article reports on Kaspersky researchers' analysis of threats targeting small and medium-sized businesses. From January through April 2026, Kaspersky security solutions detected 33,352 attacks in which malware or potentially unwanted software was disguised as one of five popular AI services, nearly five times the comparable 2025 figure. Claude and OpenClaw are identified among the lures, alongside phishing and scam campaigns targeting businesses.

### Source excerpt

На прошлой неделе исследователи "Лаборатории Касперского" опубликовали разбор ландшафта угроз для малого и среднего бизнеса. По данным отчета, небольшие компании остаются мишенью как для операторов массовых вредоносных кампаний, так и для тех, кто использует подрядчика как точку входа в инфраструктуру более крупной организации. Авторы статьи отдельно отмечают, что в 2026 году одной из главных приманок стали популярные ИИ-сервисы. Главная новость в отчете: с января по апрель 2026 года защитные решения "Лаборатории Касперского" зафиксировали 33 352 атаки на малый и средний бизнес, в которых вредоносное или потенциально нежелательное ПО маскировалось под один из пяти популярных ИИ-сервисов. Это почти в пять раз больше, чем за аналогичный период 2025 года. Всего было обнаружено более 1100 уникальных образцов такого ПО -- на 21% больше, чем в прошлом году. В основном это разнообразные троянские программы, в том числе загрузчики, которые подтягивают на скомпрометированную машину дополнительную нагрузку. Среди приманок авторы называют сервис Claude и приложение OpenClaw (бывший Clawdbot, он же Moltbot), ставшие особо популярными в 2026 году. Как и следовало ожидать, чем более на слуху конкретный инструмент, тем выше вероятность столкнуться с его поддельной копией в Сети. Разбивку по типам популярных сервисов, под которые маскировались вредоносные кампании, можно посмотреть на скриншоте выше. Читать далее

## Using local Gemma and Qwen models to triage OpenClaw issues and pull requests

DevFeed: [Using local Gemma and Qwen models to triage OpenClaw issues and pull requests](<https://devfeed.tech/articles/we-got-local-models-to-triage-the-openclaw-repo-for-free-7341.md>)

Original publisher: [Read original article](<https://huggingface.co/blog/local-models-pr-triage>)

Author: Onur Solmaz; ben burtenshaw; shaun smith

Published: 2026-06-22T00:00:00Z

Content type: article

Language: en

Sources: [Hugging Face - Blog](<https://devfeed.tech/sources/hugging-face-blog.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [Agent Harness](<https://devfeed.tech/topics/agent-harness.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [gemma](<https://devfeed.tech/topics/gemma.md>), [qwen](<https://devfeed.tech/topics/qwen.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agent-harness](<https://devfeed.tech/tags/agent-harness.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [free](<https://devfeed.tech/tags/free.md>), [gemma](<https://devfeed.tech/tags/gemma.md>), [guide](<https://devfeed.tech/tags/guide.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-collab](<https://devfeed.tech/tags/open-source-collab.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [qwen](<https://devfeed.tech/tags/qwen.md>), [real-time](<https://devfeed.tech/tags/real-time.md>)

### AI overview

The article describes using local Gemma and Qwen models in an agent harness to classify and triage issues and pull requests in the OpenClaw repository. It presents local execution as a way to support near-real-time notifications without relying on a paid hosted-model quota, using structured outputs and a finite label set.

### Source excerpt

We're on a journey to advance and democratize artificial intelligence through open source and open science.

## Encrypted reasoning fields in LLM APIs: a hobby project exploring signed thinking blocks

DevFeed: [Encrypted reasoning fields in LLM APIs: a hobby project exploring signed thinking blocks](<https://devfeed.tech/articles/let-s-talk-about-encrypted-reasoning-29096.md>)

Original publisher: [Read original article](<https://blog.cryptographyengineering.com/2026/05/29/fooling-around-with-encrypted-reasoning-blobs/>)

Author: Matthew Green

Published: 2026-05-29T03:52:19Z

Content type: opinion

Language: en

Sources: [Matthew Green](<https://devfeed.tech/sources/matthew-green.md>)

Topics: [Large Language Model](<https://devfeed.tech/topics/llm.md>), [API](<https://devfeed.tech/topics/api.md>), [Prompt Engineering](<https://devfeed.tech/topics/prompt-engineering.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [Security](<https://devfeed.tech/topics/security.md>), [OpenAI](<https://devfeed.tech/topics/openai.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [api](<https://devfeed.tech/tags/api.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [chain-of-thought](<https://devfeed.tech/tags/chain-of-thought.md>), [claude](<https://devfeed.tech/tags/claude.md>), [coding-agents](<https://devfeed.tech/tags/coding-agents.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [frontier-llm-apis](<https://devfeed.tech/tags/frontier-llm-apis.md>), [llms](<https://devfeed.tech/tags/llms.md>), [openai](<https://devfeed.tech/tags/openai.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [prompt](<https://devfeed.tech/tags/prompt.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This opinion article describes a hobby project investigating encrypted or signed reasoning fields exposed by LLM APIs. It discusses configuring an OpenClaw agent to use Claude, comparing Claude's Messages API with OpenAI's Responses API, and examining hidden chain-of-thought data. An August 11, 2026 update says European researchers developed a working attack inspired by the post.

### Source excerpt

Update August 11, 2026: A group of researchers from all over Europe were inspired by this post, and actually turned it into a real working attack! Check out their writeup and paper here. This is a quick post I wanted to write about a hobby project I spent a weekend on. It has little to ... Continue reading Let's talk about encrypted reasoning ->

## OpenClaw is not for the enterprise | Tyler Rockwood, Redpanda

DevFeed: [OpenClaw is not for the enterprise | Tyler Rockwood, Redpanda](<https://devfeed.tech/articles/openclaw-is-not-for-the-enterprise-tyler-rockwood-redpanda-12723.md>)

Original publisher: [Read original article](<https://www.redpanda.com/blog/openclaw-not-for-enterprise>)

Author: Tyler Rockwood

Published: 2026-04-14T00:00:00Z

Content type: opinion

Language: en

Sources: [Redpanda](<https://devfeed.tech/sources/redpanda.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [agent observability](<https://devfeed.tech/topics/agent-observability.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [gateway](<https://devfeed.tech/tags/gateway.md>), [observability](<https://devfeed.tech/tags/observability.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [security](<https://devfeed.tech/tags/security.md>), [thought-leadership](<https://devfeed.tech/tags/thought-leadership.md>)

### AI overview

The article argues that OpenClaw's sandboxing is not an adequate enterprise security model. It proposes a governed architecture centered on a gateway that controls agent access, provides observability, enforces rate limits and guardrails, and supports centralized shutdown of rogue agents.

### Source excerpt

A sandbox isn't a security model. OpenClaw runs great on a developer's machine, but it isn't made for enterprise scale. Here's what is.

## How open-strix handles long-lived agent memory by rebuilding context

DevFeed: [How open-strix handles long-lived agent memory by rebuilding context](<https://devfeed.tech/articles/how-to-forget-33488.md>)

Original publisher: [Read original article](<https://timkellogg.me/blog/2026/04/14/forgetting>)

Published: 2026-04-14T00:00:00Z

Content type: opinion

Language: en

Sources: [Tim Kellogg](<https://devfeed.tech/sources/tim-kellogg.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [context](<https://devfeed.tech/topics/context.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [caching](<https://devfeed.tech/tags/caching.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [context](<https://devfeed.tech/tags/context.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>)

### AI overview

The article contrasts open-strix with open-claw and other agent systems. It argues that open-strix prioritizes remembering by rebuilding context with a sliding window, avoiding abrupt context compaction and relying less on sequential prompt caching.

### Source excerpt

Most agent frameworks optimize for recall. Open-strix optimizes for forgetting -- and that turns out to be the whole trick.

## How to build an autonomous AI agent like OpenClaw (from scratch)

DevFeed: [How to build an autonomous AI agent like OpenClaw (from scratch)](<https://devfeed.tech/articles/how-to-build-an-autonomous-ai-agent-like-openclaw-from-scratch-33569.md>)

Original publisher: [Read original article](<https://blog.algomaster.io/p/how-to-build-an-autonomous-ai-agent-like-openclaw>)

Author: Ashish Pratap Singh

Published: 2026-04-07T04:20:00Z

Content type: tutorial

Language: en

Sources: [AlgoMaster Newsletter](<https://devfeed.tech/sources/algomaster-newsletter.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [Tutorial](<https://devfeed.tech/topics/tutorial.md>), [coding](<https://devfeed.tech/topics/coding.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [Tool](<https://devfeed.tech/topics/tool.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [coding](<https://devfeed.tech/tags/coding.md>), [context](<https://devfeed.tech/tags/context.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [llm](<https://devfeed.tech/tags/llm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [prompt](<https://devfeed.tech/tags/prompt.md>), [security](<https://devfeed.tech/tags/security.md>), [telegram](<https://devfeed.tech/tags/telegram.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

This tutorial explains how to build Tiny-OpenClaw, a simplified autonomous AI agent inspired by OpenClaw. It describes capabilities such as web browsing, form filling, persistent memory, Skills, and Telegram communication, while deliberately excluding full system access because of security risks.

### Source excerpt

This is a guest post by Dr.

## Liberate your OpenClaw

DevFeed: [Liberate your OpenClaw](<https://devfeed.tech/articles/liberate-your-openclaw-7331.md>)

Original publisher: [Read original article](<https://huggingface.co/blog/liberate-your-openclaw>)

Author: Clem 🤗; ben burtenshaw; Pedro Cuenca; Jeff Boudier; merve; Niels Rogge; Victor Mustar; Mishig ᠮᠢᠰᠾᠢᠭ

Published: 2026-03-27T00:00:00Z

Content type: tutorial

Language: en

Sources: [Hugging Face - Blog](<https://devfeed.tech/sources/hugging-face-blog.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [hugging face](<https://devfeed.tech/topics/hugging-face.md>), [inference-providers](<https://devfeed.tech/topics/inference-providers.md>), [llama.cpp](<https://devfeed.tech/topics/llama-cpp.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [guide](<https://devfeed.tech/tags/guide.md>), [hugging-face](<https://devfeed.tech/tags/hugging-face.md>), [inference-providers](<https://devfeed.tech/tags/inference-providers.md>), [llama-cpp](<https://devfeed.tech/tags/llama-cpp.md>), [local-ai](<https://devfeed.tech/tags/local-ai.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [server](<https://devfeed.tech/tags/server.md>)

### AI overview

This tutorial explains how to restore OpenClaw agents using open models through Hugging Face Inference Providers or by running models locally with llama.cpp. It compares hosted and local approaches, covering privacy, cost, hardware, model selection, configuration, and local server setup.

### Source excerpt

We're on a journey to advance and democratize artificial intelligence through open source and open science.

## DigitalOcean at NVIDIA GTC 2026: Building the AI Factory for the Agentic Era

DevFeed: [DigitalOcean at NVIDIA GTC 2026: Building the AI Factory for the Agentic Era](<https://devfeed.tech/articles/digitalocean-at-nvidia-gtc-2026-building-the-ai-factory-for-the-agentic-era-19862.md>)

Original publisher: [Read original article](<https://www.digitalocean.com/blog/building-ai-factory-for-agentic-era-nvidia-gtc>)

Author: Vinay Kumar, DigitalOcean Chief Product & Technology Officer

Published: 2026-03-16T20:35:55Z

Content type: release

Language: en

Sources: [DigitalOcean](<https://devfeed.tech/sources/digitalocean.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Inference](<https://devfeed.tech/topics/inference.md>), [Nvidia](<https://devfeed.tech/topics/nvidia.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [model-deployment](<https://devfeed.tech/topics/model-deployment.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [NemoClaw](<https://devfeed.tech/topics/nemoclaw.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [OpenShell](<https://devfeed.tech/topics/openshell.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [announce](<https://devfeed.tech/tags/announce.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [digitalocean](<https://devfeed.tech/tags/digitalocean.md>), [inference](<https://devfeed.tech/tags/inference.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [models](<https://devfeed.tech/tags/models.md>), [nemoclaw](<https://devfeed.tech/tags/nemoclaw.md>), [nvidia](<https://devfeed.tech/tags/nvidia.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [openshell](<https://devfeed.tech/tags/openshell.md>), [product-updates](<https://devfeed.tech/tags/product-updates.md>), [production](<https://devfeed.tech/tags/production.md>), [services](<https://devfeed.tech/tags/services.md>)

### AI overview

DigitalOcean announces an expansion of its AI inference capabilities in partnership with NVIDIA. The article describes an AI Factory for production AI workloads, including agentic workflows, OpenClaw deployment, NemoClaw, and the OpenShell runtime.

### Source excerpt

A seamless path for builders: Start building on build.nvidia.com, Deploy to DigitalOcean The landscape of artificial intelligence has shifted from static models to dynamic, long-running agents. At DigitalOcean, our mission is to provide developers with a purpose-built, agentic, inference cloud for running AI in production--without the operational overhead or complex cost structures of traditional infrastructure. Today, at NVIDIA GTC 2026, we are excited to announce a massive expansion of our inference capabilities in partnership with NVIDIA. We are moving beyond basic infrastructure; we are building an AI Factory designed specifically to support AI builders and power the next generation of autonomous agents. The Proven Home for AI Agents DigitalOcean is rapidly becoming the dominant player and preferred deployment destination for agentic workflows. When the open-source agent OpenClaw (formerly Clawdbot) went viral, we recognized the market's need for frictionless deployment. In under 36 hours, we shipped a production-ready 1-Click Droplet to our Marketplace. The results demonstrate our reach: OpenClaw has driven 43,000+ total deployments on DigitalOcean with over 11,000 active OpenClaw deployments in production today. Builders aren't just deploying models; they are utilizing our ecosystem, expanding into adjacent services like Backups, Snapshots, and Gradient AITM Serverless Inference to support their agentic workloads. DigitalOcean and NVIDIA are also working together on NVIDIA NemoClaw, an open source stack that simplifies running OpenClaw always-on assistants, more safely, with a single command. The NVIDIA OpenShell runtime offers a secure environment to run autonomous agents and open source models, then deploy seamlessly to DigitalOcean. Investing in the "AI Factory": Deep Cloud & Inference Integration Why is DigitalOcean uniquely positioned to win in this new marketplace? We are investing deeply to integrate traditional cloud primitives with our state-of-the-art

## Laravel February Product Updates

DevFeed: [Laravel February Product Updates](<https://devfeed.tech/articles/laravel-february-product-updates-3766.md>)

Original publisher: [Read original article](<https://laravel.com/blog/laravel-february-product-updates>)

Author: Laravel Team

Published: 2026-03-02T16:19:42Z

Content type: news

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [API](<https://devfeed.tech/topics/api.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [vercel ai sdk](<https://devfeed.tech/topics/vercel-ai-sdk.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [MySQL](<https://devfeed.tech/topics/mysql.md>), [Svelte](<https://devfeed.tech/topics/svelte.md>), [vs-code](<https://devfeed.tech/topics/vs-code.md>), [observability](<https://devfeed.tech/topics/observability.md>), [npm](<https://devfeed.tech/topics/npm.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [api](<https://devfeed.tech/tags/api.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [code](<https://devfeed.tech/tags/code.md>), [database](<https://devfeed.tech/tags/database.md>), [developer-experience](<https://devfeed.tech/tags/developer-experience.md>), [ecosystem](<https://devfeed.tech/tags/ecosystem.md>), [embeddings](<https://devfeed.tech/tags/embeddings.md>), [framework](<https://devfeed.tech/tags/framework.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integration](<https://devfeed.tech/tags/integration.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mysql](<https://devfeed.tech/tags/mysql.md>), [product](<https://devfeed.tech/tags/product.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

Laravel's February product updates include AI SDK default model configuration, a Svelte starter kit, and VS Code test runner integration. Laravel Cloud adds a programmable API and CLI, with a MySQL 8.0 end-of-life notice recommending MySQL 8.4 LTS. Forge adds npm private package support, MySQL 9 provisioning, and OpenClaw servers, while Nightwatch adds an MCP server, Linear integration, and per-user filtering.

### Source excerpt

Laravel Cloud API & CLI, MySQL 8.4 upgrade notice, Forge MySQL 9, Nightwatch MCP & Linear integration, and new Framework AI updates.

## How to Set Up OpenClaw for Secure, Persistent, and Deterministic Workflows

DevFeed: [How to Set Up OpenClaw for Secure, Persistent, and Deterministic Workflows](<https://devfeed.tech/articles/build-your-ai-agent-the-right-way-26200.md>)

Original publisher: [Read original article](<https://craftbettersoftware.com/p/build-your-ai-agent-the-right-way>)

Author: Daniel Moka

Published: 2026-03-02T06:20:17Z

Content type: tutorial

Language: en

Sources: [Craft Better Software](<https://devfeed.tech/sources/craft-better-software.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Security](<https://devfeed.tech/topics/security.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Mac Mini](<https://devfeed.tech/topics/mac-mini.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [docker](<https://devfeed.tech/tags/docker.md>), [installation](<https://devfeed.tech/tags/installation.md>), [llms](<https://devfeed.tech/tags/llms.md>), [mac-mini](<https://devfeed.tech/tags/mac-mini.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [pairing](<https://devfeed.tech/tags/pairing.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A practical guide to setting up OpenClaw for real work. It recommends using a Mac mini or VPS, running OpenClaw in Docker, configuring the agent's identity, and applying security boundaries such as keeping the gateway private and requiring pairing.

### Source excerpt

Setting Up Your AI Assistant of OpenClaw Correctly for Real Work

## How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware

DevFeed: [How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware](<https://devfeed.tech/articles/how-a-malicious-google-skill-on-clawhub-tricks-users-into-installing-malware-7863.md>)

Original publisher: [Read original article](<https://snyk.io/blog/clawhub-malicious-google-skill-openclaw-malware/>)

Author: Liran Tal

Published: 2026-02-10T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Google](<https://devfeed.tech/topics/google.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [interest](<https://devfeed.tech/tags/interest.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Snyk researchers describe an active supply chain attack targeting OpenClaw users through a malicious Google integration skill distributed on ClawHub. The skill uses instructions in SKILL.md to fabricate a prerequisite, persuade users to run an installer, and deploy malware across Windows and macOS/Linux systems.

### Source excerpt

Breaking: Snyk researchers uncover a malicious "Google" skill on ClawHub that tricks users into installing malware via a fake OpenClaw dependency. Learn how the attack works and how to protect your AI agents.

## DigitalOcean launches OpenClaw on App Platform for elastic scaling and production operations

DevFeed: [DigitalOcean launches OpenClaw on App Platform for elastic scaling and production operations](<https://devfeed.tech/articles/run-multiple-openclaw-ai-agents-with-elastic-scaling-and-safe-defaults-without-managing-infrastructure-19926.md>)

Original publisher: [Read original article](<https://www.digitalocean.com/blog/openclaw-digitalocean-app-platform>)

Author: DigitalOcean

Published: 2026-02-05T18:48:11Z

Content type: release

Language: en

Sources: [DigitalOcean](<https://devfeed.tech/sources/digitalocean.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [Digital Ocean](<https://devfeed.tech/topics/digital-ocean.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Messaging](<https://devfeed.tech/topics/messaging.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [digitalocean](<https://devfeed.tech/tags/digitalocean.md>), [discord](<https://devfeed.tech/tags/discord.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [product-updates](<https://devfeed.tech/tags/product-updates.md>), [slack](<https://devfeed.tech/tags/slack.md>), [telegram](<https://devfeed.tech/tags/telegram.md>), [whatsapp](<https://devfeed.tech/tags/whatsapp.md>)

### AI overview

DigitalOcean is launching OpenClaw on App Platform to help teams operate always-on, multi-agent AI assistants with elastic scaling, safer defaults, predictable instance-based pricing, and simpler operations.

### Source excerpt

OpenClaw has quickly become a popular open-source framework for building personal AI assistants connected to services as well as messaging platforms such as Telegram, WhatsApp, Discord, and Slack. As more developers move from local experiments to always-on assistants, the challenge shifts from building an agent to operating one reliably over time, often across multiple agents handling different workstreams. Once an assistant is running continuously, handling real traffic, and coordinating tools or APIs, new questions surface quickly: How do you keep it running without constantly managing servers? How do you scale from one assistant to multiple agents without re-architecting? How do you apply security and access controls you can trust by default? How do you grow usage without turning operations into a second job? How do you scale agents without losing visibility or predictability into costs? Today, we're launching OpenClaw on DigitalOcean App Platform to answer these questions. It is designed for this stage--helping teams move from proof of concept to sustained production operation with elastic scaling, safe defaults, and simpler day-to-day operations. Further, OpenClaw on App Platform brings cost predictability to always-on AI systems. Instead of variable, request-driven pricing that can spike unexpectedly as usage grows, App Platform uses clear, instance-based pricing. Teams can understand how costs change as they add agents or increase capacity without surprises. OpenClaw on App Platform: Built for always-on, multi-agent AI systems As OpenClaw usage grows, developers naturally reach different stages of operation. Some teams want a fast, VM-based deployment with full system control. That's exactly what the 1-Click Deploy OpenClaw on a DigitalOcean Droplet® server provides: a secure, hardened environment where you own the virtual machine and manage the underlying infrastructure directly. Other teams reach a point where infrastructure ownership becomes unnecessary ove

## 280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII

DevFeed: [280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII](<https://devfeed.tech/articles/280-leaky-skills-how-openclaw-clawhub-are-exposing-api-keys-and-pii-8040.md>)

Original publisher: [Read original article](<https://snyk.io/blog/openclaw-skills-credential-leaks-research/>)

Author: Luca Beurer-Kellner; Aleksei Kudrinskii; Marco Milanta; Kristian Bonde Nielsen; Hemang Sarkar; Liran Tal

Published: 2026-02-05T18:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [interest](<https://devfeed.tech/tags/interest.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [pii](<https://devfeed.tech/tags/pii.md>), [secrel](<https://devfeed.tech/tags/secrel.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [skills](<https://devfeed.tech/tags/skills.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

Snyk reports that 283 of 3,984 skills in the ClawHub marketplace, or 7.1%, contain critical flaws that expose API keys, passwords, credit card numbers, and other sensitive information through LLM context and plaintext logs. The article explains how OpenClaw agent skills can instruct agents to mishandle secrets and describes a credential-leaking email skill as an example.

### Source excerpt

Discover how 7.1% of AI agent skills are designed to leak secrets, PII, and API keys through LLM context. Learn to defend with Evo & mcp-scan.

## Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise

DevFeed: [Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise](<https://devfeed.tech/articles/snyk-finds-prompt-injection-in-36-1467-malicious-payloads-in-a-toxicskills-study-of-agent-skills-supply-chain-compromise-8218.md>)

Original publisher: [Read original article](<https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/>)

Author: Luca Beurer-Kellner; Aleksei Kudrinskii; Marco Milanta; Kristian Bonde Nielsen; Hemang Sarkar; Liran Tal

Published: 2026-02-05T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [ai](<https://devfeed.tech/tags/ai.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [developer](<https://devfeed.tech/tags/developer.md>), [malware](<https://devfeed.tech/tags/malware.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

Snyk's ToxicSkills audit examined 3,984 AI agent skills and found that 36.82% had at least one security flaw. The research identified malware, credential theft, prompt injection, exposed secrets, backdoors, and data exfiltration affecting users of OpenClaw, Claude Code, and Cursor.

### Source excerpt

Snyk's ToxicSkills research reveals 36% of AI agent skills contain security flaws, including 1,467 vulnerable skills and active malicious payloads targeting OpenClaw, Claude Code, and Cursor users.

[Next page](<https://devfeed.tech/topics/openclaw.md?cursor=WyIyMDI2LTAyLTA1VDA1OjAwOjAwKzAwOjAwIiwgImEzN2NiMDJlLTdjZjktNDkzYS1hODhkLWNiMWY4OTgyZjViYiJd>)