knowledge-base/wiki/tools/openclaw.md
Hector 58b72f783e ingest(raw): Jun Song — MLX MoE optimization & local AI info gap
- raw: xpost/2026-06-29_junsong-mlx-moe-local-ai-info-gap.md
- wiki NEW: concepts/llm/mlx-moe-local-ai-optimization.md
- wiki: index.md updated (45th update), log.md updated
- Key insight: MLX optimized for MoE not dense; Minimax-M3.0 (dq) +
  DeepSeek-v4-Flash (dq) run smooth on Mac; info gap thesis validates
  wiki curation mission
2026-06-30 08:51:57 +02:00

330 lines
16 KiB
Markdown

---
created: 2026-06-16
updated: 2026-06-30
sources: [other/2026-06-16_openclaw-releases-v2026.6.8.md, blog/2026-06-30_perplexity-openclaw-mobile-apps.md]
tags: [tool, openclaw, platform, releases, github, npm, security, model-routing, mobile-apps, ios, android, node-pairing, clawhub]
---
# OpenClaw
> **Stand: 2026-06-30** — aktuelle Stable: **v2026.6.8** (Release 16.06.2026, 16:32 UTC)
> **Mobile Apps:** Native iOS + Android Apps veröffentlicht am 29.06.2026 (siehe [Mobile Apps Sektion](#mobile-apps-ios--android) unten)
> Quelle: <https://github.com/openclaw/openclaw/releases>
> npm: <https://www.npmjs.com/package/openclaw>
OpenClaw ist die **Plattform**, auf der unser Hector-Setup läuft. Diese Seite
ist die zentrale Referenz für Versions-Status, Architektur-Patterns und
Release-relevante Änderungen, die unser Setup betreffen.
> **Aktuelle Version tracken:** Releases erscheinen in kurzen Zyklen (alle 2-3
> Tage im Juni 2026), immer mit stabilisierendem Fix-Fokus. Wir laufen derzeit
> auf `ollama/minimax-m3` als Fallback-Modell — Releases mit Provider-Routing-
> Änderungen (z.B. OpenRouter/Vertex-Prefix-Normalisierung in 2026.6.8) sind
> besonders zu beachten.
## Verwandte Wiki-Seiten
- [[../architecture/model-routing.md]] — OpenClaw Provider-Normalisierung, GLM-5.2-Routing
- [[../architecture/memory-system.md]] — S2 (OpenClaw built-in Memory), QMD-JSON-Search
- [[../concepts/llm/glm-5.2-zai-coding-model.md]] — GLM 5.2 mit OpenClaw-Integration
- [[../concepts/llm/llm-knowledge-base.md]] — OpenClaw native raw Memory Wiki source pages
- [[../concepts/directives/openclaw-financial-bots-policy.md]] — Financial-Bot-Restriktionen
- [[../architecture/agent-orchestration.md]] — Subagent-Spawning-Patterns
## Externe Ressourcen
- **Repository:** <https://github.com/openclaw/openclaw>
- **Releases:** <https://github.com/openclaw/openclaw/releases>
- **npm-Package:** <https://www.npmjs.com/package/openclaw>
- **Maintainer:** [@vincentkoc](https://github.com/vincentkoc) (Lead), [@steipete](https://github.com/steipete) (macOS Builds)
- **Discord / Telegram Bots:** siehe Channel-Plugins in den Releases
---
## Mobile Apps: iOS + Android (ab 29.06.2026)
Die OpenClaw Foundation hat am 29.06.2026 **native iOS- und Android-Apps** veröffentlicht. OpenClaw ist damit das erste Open-Source-KI-Agent-Projekt mit Companion-App auf beiden großen mobilen Plattformen.
> Quelle: [Perplexity Discover](https://www.perplexity.ai/discover/you/openclaw-launches-mobile-apps-z.LpO8wdT6mvjhXxxMuqNA) (aggregiert aus 9to5google, 9to5mac, conscia.com, unit42.paloaltonetworks.com). Siehe `raw/blog/2026-06-30_perplexity-openclaw-mobile-apps.md`.
### Funktionsumfang
- **Gateway-Pairing** via QR-Code oder Setup-Code — identisch mit unserem `node-connect`-Skill-Pattern
- **Echtzeit-Voice-Interaktion** mit dem Agenten
- **Action Approvals vom Handy** — Alternative zu Telegram-Native-Approvals
- **Device Capabilities als Node-Features:** Kamera, Bildschirm, Standort, Fotos, Kontakte, Kalender, Erinnerungen
- **Local-First:** Eigener Gateway, eigene API-Keys, keine Daten über Firmen-Server
### Plattform-Status
| Plattform | Geräte | Status | Bewertung |
|-----------|--------|--------|------------|
| **iOS** | iPhone, iPad, Apple Watch | Polierter | App Store |
| **Android** | Core-Funktionalität | ⚠️ Early-Stage | 2.2★ Play Store ("buggy, difficult to pair") |
### Historischer Meilenstein
- **Spät 2025:** OpenClaw als CLI-Tool von Peter Steinberger gestartet
- **Februar 2026:** OpenAI übernahm das Projekt, unterstützt als Open-Source unter der OpenClaw Foundation
- **Juni 2026:** 346K+ GitHub Stars, 3.2M+ aktive Nutzer
- **29.06.2026:** Mobile Apps als Schritt zur Consumer-Accessibility
### ClawHub Security-Kontext
Der Mobile-App-Launch erfolgt vor einem Hintergrund anhaltender Security-Bedenken rund um **ClawHub** (Skill-Marketplace):
| Datum | Quelle | Befund |
|-------|--------|--------|
| 22.06.2026 | Palo Alto Unit 42 | 5 malicious skills bypassed screening (macOS Infostealer, Financial Exploitation) |
| 2026 (kumuliert) | Forschung | 800+ malicious skills (~20% des ClawHub-Registries) |
| 2026 | University of Maryland | 84.2% der Vulnerabilities in Natural-Language-Instructions, nicht in Code |
| Mai 2026 | Cloud Security Alliance | Chain von 4 CVEs dokumentiert (insgesamt 6 CVEs in 2026) |
**Für unser Setup:** Wir nutzen Skill Workshop mit gated + validated symlink writes (seit v2026.6.7). Das ist eine Mitigation gegen executable-code-Vektoren, aber **kein Schutz** gegen natural-language-injection in Skill-Instructions — 84.2% der Vulnerabilities liegen dort. Siehe [[../concepts/directives/openclaw-financial-bots-policy.md]].
### Implikationen für unser Setup
1. **Node-Pairing:** Die App ist die Consumer-Schnittstelle zum Gateway. Unser `node-connect`-Skill adressiert genau diese Pairing-Methode.
2. **Action Approvals:** Bislang über Telegram (nativeapprovals). Mit der App als Alternative — interessant für Situationen wo Telegram nicht ideal ist.
3. **Apple Watch:** Approval-Notifications am Handgelenk als weitere Option.
4. **Android:** Early-Stage 2.2★ Rating beim Pairing — beobachten, falls wir Android-Nodes einsetzen.
---
## Architektur-Übersicht
OpenClaw ist eine **Multi-Channel AI-Agent-Plattform** mit folgenden Hauptkomponenten:
| Komponente | Funktion | Für uns relevant? |
|---|---|---|
| **Gateway** | HTTP-WS-RPC-Server, Approval-Runtime, Auth | ✅ Aktiv |
| **Agent Runtime** | Session-Lifecycle, Subagent-Spawning, Tool-Calls | ✅ Aktiv |
| **Channel Plugins** | Telegram, Discord, WhatsApp, Slack, iMessage, Feishu, Mattermost, LINE, QQBot, Teams | ✅ Telegram + Discord aktiv |
| **Provider-Adapter** | OpenRouter, Anthropic, OpenAI, Google, ZAI, Moonshot, Ollama, LM Studio, Codex, … | ✅ OpenRouter, OpenAI, Ollama |
| **Memory** | S2 Built-in (Voyage Embeddings), QMD JSON Search | ✅ S2 primär |
| **Skill Workshop** | Gated + validated symlink writes, Version-Drift-Reporting | ✅ Aktiv |
| **Plugin Manager (ClawHub)** | Managed plugin install/update mit dependency-evidence | ✅ Codebase-Update via npm |
| **CLI Backends** | Claude CLI, Codex native shell approvals, Trajectory-Export | ⚠️ Gelegentlich |
## Aktueller Release-Status (Top 5, 2026-06-12 bis 2026-06-16)
| Tag | Datum | Typ | Kerninhalt |
|---|---|---|---|
| **v2026.6.8** | 16.06.2026 16:32 UTC | **stable** | GLM-5.2 + Claude Haiku 4.5 Support, Provider-Prefix-Normalization, Telegram rich-message delivery, QMD transient mode, raw Memory Wiki source pages als source evidence |
| v2026.6.8-beta.2 | 16.06.2026 01:50 UTC | prerelease | Beta-Build für v2026.6.8 |
| v2026.6.8-beta.1 | 14.06.2026 22:45 UTC | prerelease | Beta-Build für v2026.6.8 |
| v2026.6.7-beta.1 | 13.06.2026 09:42 UTC | prerelease | **Kimi K2.7 Code added**, Discord thread-titles, Anthropic thinking replay repair, Skill Workshop symlink gating |
| **v2026.6.6** | 12.06.2026 11:04 UTC | **stable** | **Security-Release**: exec approvals fail closed, MCP stdio, ACP bypasses, Telegram account-scoped topics, iMessage recovery |
Vollständige Release-Bodies: siehe `raw/other/2026-06-16_openclaw-releases-v2026.6.8.md`.
---
## Was hat sich seit unserer letzten Doku geändert?
Unsere Wiki-Bestandsaufnahme (Stand 2026-06-13) hatte noch keine `tools/openclaw.md`-
Seite. Die Doku-Aktualisierung konzentriert sich auf **plattformrelevante Änderungen
der letzten 5 Releases**, mit Schwerpunkt auf das, was unser Setup direkt betrifft.
### 1. Provider-Routing: GLM-5.2 offiziell supported (v2026.6.8)
OpenClaw hat **GLM-5.2** in den Provider-Catalog aufgenommen und behandelt das
Modell gleichberechtigt zu Claude/OpenAI. Details: [[../concepts/llm/glm-5.2-zai-coding-model.md]].
**Implikation für unser Routing:**
```
Bisher: openrouter/auto → zai/glm-5-turbo → moonshot/moonshot-v1-auto → ...
Mit v2026.6.8: GLM-5.2 ist direkt routeable, provider-prefix normalization greift
für OpenRouter UND Google Vertex Pfade
```
Siehe [[../architecture/model-routing.md]] für den aktualisierten Routing-Plan.
### 2. Provider-Prefix-Normalisierung (v2026.6.8)
OpenClaw normalisiert jetzt **provider-qualified model IDs** über OpenRouter und
Google Vertex Pfade. Das bedeutet: ein `openrouter/anthropic/claude-3.5-sonnet`
wird intern konsistent zu `anthropic/claude-3.5-sonnet` für Runtimes, die bare
IDs brauchen.
**Wichtig für unser Setup:** Wir nutzen `ollama/minimax-m3` (Primary-Fallback) und
`ollama/glm-5.1` (Primary) — die Prefix-Normalisierung betrifft uns nur, falls
wir auf OpenRouter-Pfade umschwenken (was aktuell nicht geplant ist, da unsere
Failover-Chain `ollama/minimax-m3` ist). **Kein Action-Item.**
### 3. QMD Memory Search: stabilisiert in transient mode (v2026.6.7, v2026.6.8)
**QMD** = OpenClaws Queryable Memory Database (JSON-basiert). Vorher konnte QMD
in transient mode (z.B. während Reindex) komplett ausfallen, jetzt bleibt es
verfügbar — Startup-Failures werden zusätzlich zu Fallback-Errors reported.
**Implikation für S2:** Unsere S2-Memory-Schicht (OpenClaw built-in, Voyage
voyage-3-lite Embeddings) profitiert direkt. Details: [[../architecture/memory-system.md]].
### 4. Raw Memory Wiki source pages: nicht mehr "malformed" (v2026.6.8)
**Bisher:** Raw Memory Wiki source pages (also: Wiki-Pages, die als Quelle in
anderen Wiki-Pages referenziert werden) wurden vom Indexer manchmal als
"malformed" markiert, was die Suche beeinträchtigte.
**Jetzt:** Raw Memory Wiki source pages werden explizit als **source evidence**
behandelt und korrekt indexiert.
**Implikation für uns:** Genau das Wiki-Pattern, das wir hier im RamaDama-
Knowledge-Base praktizieren (`raw/ → wiki/`), wird von OpenClaw nativ
unterstützt. Siehe [[../concepts/llm/llm-knowledge-base.md]].
### 5. Skill Workshop: symlink writes gated + validated (v2026.6.7)
**Vorher:** Skill-Workshop-Symlink-Writes konnten ungeprüft schreiben, was bei
ungültigen Pfaden zu kaputten Skills führte.
**Jetzt:** Writes werden vorab validiert + gegated, Rollback-Metadaten erst nach
Validation geschrieben. Retired Configs erzeugen nur noch Warnings, keine
Failures mehr.
**Implikation für uns:** Wir nutzen Skill Workshop aktiv. Robustheit verbessert
sich spürbar — failed skills crashen das Setup nicht mehr.
### 6. Admin-Privilegien für HTTP session/model override (v2026.6.8)
**Neu:** HTTP-Endpoints für session/model override verlangen jetzt Admin-Privilegien.
Bisher war das implizit durch Gateway-Auth geschützt.
**Wichtig für uns:** Falls wir HTTP-Override-Surfaces (z.B. für Cron-Trigger)
nutzen, müssen wir prüfen, ob die Auth-Stufe ausreicht. **Aktuell nutzen wir
keine HTTP-Override-Endpoints** — keine Aktion erforderlich.
### 7. Telegram rich-message delivery (v2026.6.6 - v2026.6.8)
**Across 3 releases:** Account-scoped topics, streamed text survives tool calls,
expandable blockquotes, spooled replay, durable dispatch dedupe im SDK, intent-
preserving line breaks, prompt-preserving CLI backend delivery, retired native
draft migration, safer rich-media boundaries.
**Implikation für uns:** Telegram ist unser Hauptkanal. Wir profitieren von
besserer Formatierung und weniger Delivery-Brittle-Verhalten ohne Action-Item.
### 8. Subagent-Verhalten: trusted thinking override fallback (v2026.6.8)
Wenn ein trusted subagent thinking override angefordert wird, das das gewählte
Provider/Model nicht unterstützt, fällt OpenClaw jetzt sauber durch die
Provider/Model-Fallback-Chain — statt mit einem harten Fehler abzubrechen.
**Implikation für uns:** Wir spawnen regelmäßig Subagents. Die Fallback-
Robustheit verbessert sich direkt. **Kein Action-Item, nur Benefit.**
### 9. Heartbeat-Dedup (v2026.6.8)
Main-session heartbeat events werden dedupliziert. Vorher konnte es bei
yielded cron media + heartbeat zu doppelten Events kommen.
**Implikation für uns:** Unsere Heartbeats (`HEARTBEAT_OK`-Pattern) sind
betroffen, aber nur in positiver Hinsicht (weniger Doppelarbeit). Kein
Action-Item.
### 10. Security: exec approvals fail closed (v2026.6.6)
**Major Security-Hardening:** Wenn ein exec-Approval-Request einen Timeout
erreicht, wird die Operation **abgelehnt** (fail closed), nicht auto-approviert.
Plus: MCP stdio hardening, ACP bypasses für deleted agents, Discord moderation,
Teams group actions, native search policy, elevated sender checks.
**Implikation für uns:** Wir haben exec-Approvals über die Gateway-Approval-
Runtime laufen. Das Fail-Closed-Pattern ist **konservativ** — bei langsamen
Approvals (z.B. durch Heartbeat-Sleep) kann es zu Ablehnungen kommen. Wir
sollten beobachten, ob unsere Approval-Latency ausreicht. **Aktuell kein
akutes Problem** — keine Aktion.
---
## Bekannte Issues + Workarounds (aus Release-Notes)
| Issue | Workaround | Quelle |
|---|---|---|
| Beta-1: ClawHub plugin-publish failed (transport plugin `setupEntry` metadata) | follow-up in 2026.6.8 fixed | v2026.6.8-beta.1 |
| Beta-2: plugin-inspector metadata failures in `@openclaw/llama-cpp-provider` | recovered via direct OpenClaw npm | v2026.6.8-beta.1 |
| Provider-prefix stripping in manchen Edge-Cases | bounded model browsing aktiviert | v2026.6.8 |
| QMD startup failures (vorher silent) | jetzt reported alongside fallback errors | v2026.6.7 |
## Rollout-Strategie für uns
Aktuell laufen wir auf der **Stable v2026.6.6** (wir sind auf dem letzten
Stable-Stand vor v2026.6.8 — laut dem Bot-Runtime-Bericht 2026-06-16).
**Empfohlene Update-Reihenfolge:**
1. **Sofort:** v2026.6.8 — bringt GLM-5.2, Provider-Prefix-Normalization,
QMD-Stabilität, Skill-Workshop-Hardening. Security-Boundaries weiter
konsolidiert.
2. **Beobachten:** v2026.6.7-beta.1 ist übersprungen (waren nicht auf dem
Beta-Train, sind direkt von v2026.6.6 auf v2026.6.8 gegangen) — Kimi
K2.7 Code verfügbar, falls wir Sub-Task-Spezialisierung wollen.
3. **Nicht relevant:** macOS/Windows native builds (wir laufen Linux auf
`bot-hector` Container, `node v24.16.0`).
**Update-Trigger:** Cron-gesteuert via `npm update openclaw` + manueller
Restart-Approval. **Aktuell: Warten auf Kai's Approval für v2026.6.8-Update.**
## Architektur-Patterns (lifetime der Plattform)
### Provider-Prefix Handling
```
openrouter/anthropic/claude-3.5-sonnet
→ normalisiert zu anthropic/claude-3.5-sonnet für bare-ID-Runtimes
→ normalisiert zu openai/gpt-4o für Codex OAuth profiles
```
Siehe [[../architecture/model-routing.md]] für unseren konkreten Routing-Plan.
### Channel Plugin Lifecycle
```
Channel-Plugin install → npm publish → ClawHub publish → Codex binaries
→ transport fixtures for drafts → rich-message delivery enable
```
### Memory Layer (S2)
```
Voyage voyage-3-lite embeddings
→ OpenClaw built-in memory (S2)
→ QMD JSON search (transient + persistent mode)
→ raw Memory Wiki source pages (als source evidence, ab v2026.6.8)
```
### Skill Workshop
```
Skill-Erstellung → Symlink-Write (gated + validated) → Rollback-Metadata
→ retired Configs: warning statt failure (ab v2026.6.7)
```
## Lizenz + Compliance
- **Lizenz-Status:** Open-Source-Kern (npm-package `openclaw`), genaue Lizenz
in der Repository-README. Stand 2026-06-16 nicht im Wiki dokumentiert —
TODO: bei Gelegenheit ergänzen.
- **Export-Controls (relevant):** Die Anthropic Mythos 5 / Fable 5 Export-
Controls (Trump-Administration 12.06.2026) betreffen **nicht** OpenClaw
direkt — aber OpenClaw kann diese Modelle als Provider-Adapter einbinden.
Siehe [[../concepts/policy/ai-regulation-2026.md]].
## Nächste Schritte
1. **Update-Entscheidung:** v2026.6.8 ja/nein → wartet auf Kai's Approval.
2. **Routing-Update:** GLM-5.2 als optionalen Sub-Routing-Knoten für Long-Context-
Tasks in `model-routing.md` einbauen (nach Update auf v2026.6.8).
3. **Memory-Doku:** S2 + QMD in `memory-system.md` ausführlicher dokumentieren
(laufende Aufgabe, siehe WMT-XXX).
4. **License-Doku:** OpenClaw-Lizenz in README oder eigener Wiki-Seite
dokumentieren (TODO, niedrige Priorität).
## Quellen
- `raw/other/2026-06-16_openclaw-releases-v2026.6.8.md` (Roh-Dump der 5 aktuellsten
Releases via GitHub REST API)
- GitHub API: <https://api.github.com/repos/openclaw/openclaw/releases>
- Web-Verify: <https://github.com/openclaw/openclaw/releases>