CVE databases: For dependency vulnerability checks
GitHub Security Advisories: For OpenClaw-specific advisories
npm audit: For JavaScript dependency vulnerabilities
Research Procedures
Version Check
Check current version: 2026.3.13 (stable)
Check latest release on GitHub
Read CHANGELOG for changes between versions
Assess breaking changes and migration requirements
Report findings using Intelligence Briefing format
Dependency Audit
Check npm for updates to core packages
Review changelogs for security fixes
Check for deprecated dependencies
Assess upgrade risk vs benefit
Community Monitoring
Review recent GitHub issues for our version
Check for common patterns in bug reports
Look for workarounds shared by other users
Monitor discussions for best practices
Security Research
Run npm audit equivalent checks
Check CVE databases for dependency vulnerabilities
Review Docker image for known vulnerabilities
Check for exposed secrets or misconfigurations
Research Output Format
All research findings should use the Intelligence Briefing format from SOUL.md:
🔍 ClawExpert IntelCategory: [Update / Security / Optimization / Bug / New Capability]
Source: [URL or reference]
Severity: [Critical / Warning / Info]
Finding: [Concise description]
Impact on us: [Specific to our setup]
Recommended action: [Exact steps]
Risk if ignored: [Consequences]
Risk of action: [What could go wrong]
Research Frequency
Version checks: Each heartbeat with research phase
Security scans: Weekly minimum, or when triggered by alerts
Community monitoring: Each research phase
Ecosystem scan: Weekly or when looking for new capabilities
1---2name: openclaw-research3description: Skill: OpenClaw Research4---5# Skill: OpenClaw Research67## Changelog8- 2026-03-19: Initial creation910## Overview11Procedures and sources for researching OpenClaw updates, ecosystem changes, and relevant intelligence.1213## Primary Sources1415### Official16- **Releases**: https://github.com/openclaw/openclaw/releases17- **Changelog**: https://github.com/openclaw/openclaw/blob/main/CHANGELOG.md18- **Issues**: https://github.com/openclaw/openclaw/issues19- **Documentation**: https://docs.openclaw.ai2021### Package Registries22- **OpenClaw npm**: https://www.npmjs.com/package/openclaw23- **mcporter npm**: https://www.npmjs.com/package/mcporter24- **stitch-mcp npm**: https://www.npmjs.com/package/@_davideast/stitch-mcp2526### Security27- **CVE databases**: For dependency vulnerability checks28- **GitHub Security Advisories**: For OpenClaw-specific advisories29- **npm audit**: For JavaScript dependency vulnerabilities3031## Research Procedures3233### Version Check341. Check current version: 2026.3.13 (stable)352. Check latest release on GitHub363. Read CHANGELOG for changes between versions374. Assess breaking changes and migration requirements385. Report findings using Intelligence Briefing format3940### Dependency Audit411. Check npm for updates to core packages422. Review changelogs for security fixes433. Check for deprecated dependencies444. Assess upgrade risk vs benefit4546### Community Monitoring471. Review recent GitHub issues for our version482. Check for common patterns in bug reports493. Look for workarounds shared by other users504. Monitor discussions for best practices5152### Security Research531. Run `npm audit` equivalent checks542. Check CVE databases for dependency vulnerabilities553. Review Docker image for known vulnerabilities564. Check for exposed secrets or misconfigurations5758## Research Output Format59All research findings should use the Intelligence Briefing format from SOUL.md:6061🔍 **ClawExpert Intel**62**Category**: [Update / Security / Optimization / Bug / New Capability]63**Source**: [URL or reference]64**Severity**: [Critical / Warning / Info]65**Finding**: [Concise description]66**Impact on us**: [Specific to our setup]67**Recommended action**: [Exact steps]68**Risk if ignored**: [Consequences]69**Risk of action**: [What could go wrong]7071## Research Frequency72- **Version checks**: Each heartbeat with research phase73- **Security scans**: Weekly minimum, or when triggered by alerts74- **Community monitoring**: Each research phase75- **Ecosystem scan**: Weekly or when looking for new capabilities
Run npx skillmds@latest add nickgallick/openclaw-research in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Skill: OpenClaw Research It is listed under Research & Search on SkillMD.
This skill has not completed SkillMD's automated safety review yet. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
nickgallick (@nickgallick) published this skill. Their other Agent Skills are listed on their SkillMD profile.