Workflow
安全与生态统一
icon
Search documents
OpenClaw版本升级“翻车”
第一财经· 2026-03-24 05:25
Core Viewpoint - The article discusses the significant update of OpenClaw, a personal AI assistant, which aims to enhance security and ecosystem integration but has faced severe issues post-upgrade due to a migration from the public npm to the official ClawHub for plugin management [3][4][5]. Group 1: Update Overview - OpenClaw has undergone its largest update since inception, focusing on a complete overhaul of its plugin system, model upgrades, security enhancements, and ecosystem integration [3]. - The new version prioritizes plugin installation from ClawHub, the official plugin market, instead of npm, to mitigate risks associated with malicious plugins [3]. Group 2: Issues Encountered - The migration to ClawHub resulted in a surge of traffic that caused widespread errors, including missing directories, plugin system failures, and issues with existing models [4]. - Developers reported that the update rendered many commonly used plugins unusable and introduced rate limits that further degraded user experience [4][5]. Group 3: Response and Future Actions - OpenClaw's developer, Peter Steinberger, acknowledged the issues and indicated that the strict rate-limiting rules would be adjusted to improve access to ClawHub [4]. - The update was prompted by increasing concerns over security in the industry, highlighted by a recent safety guideline released by the National Internet Emergency Center and the China Cybersecurity Association [5]. Group 4: Security Enhancements - In addition to the plugin ecosystem changes, OpenClaw has strengthened its sandbox environment with multiple security fixes, including enhanced permissions for Discord Slash Commands and restrictions on SMB credential handshakes on Windows [6]. - The overall focus of the new version is on developer and security orientation, but the balance between security, usability, and user experience needs further refinement [6].