v2026.9.3 treats an update as something to rehearse. Core and plugin changes can be checked in candidate state before activation, abandoned update records can be recovered, and a healthy matching Gateway is less likely to be stopped by stale update metadata.
Persistent skills have an owner
Skill Workshop content now lives in one agent-owned collection across workspaces. The release compares complete instructions and lets Doctor retire missing drafts safely. That ownership rule matters when several workspaces share one Gateway; it makes it clearer which agent may change a skill.
Browser work is visible
Live browser pages can repaint while an agent works, and native Mac tabs remain with their window across chat switches. These features help a person follow a long browser task. They do not remove the need to review a URL, a download, or a form submission before allowing it.
Cloud sessions and public links need a boundary
Repository-backed cloud sessions can check out a URL and ref with recoverable checkpoints. Public session links are explicitly published, read-only, and revocable, but anyone with the link can read the published conversation text. Review the text before sharing it and revoke the link when the work is done.
openclaw security audit
openclaw gateway status
The security guide explains why one Gateway should have one clear trust boundary. For all migration details, use the official release index.
Reference Trail
Sources and further reading
- v2026.9.3github.com
- security guidedocs.openclaw.ai
- official release indexgithub.com