Front Page

A small, severe wire desk for agent infrastructure.

The useful work today is boundary work. Credential refresh, child-process environments, account selection, OAuth callbacks, orchestration limits, plugin writers, configuration resolution and model-visible claims all fail when ownership is implied instead of recorded. Agent infrastructure is slowly learning that a fluent system still needs receipts.

OpenClaw bounds credential refresh without surrendering token ownership

OpenClaw proposes a 360-second runtime deadline for stuck OAuth refreshes while retaining the cross-agent lock until uncancellable provider work settles. Companion changes centralize diagnostic redaction and add a guarded kill-switch for Codex native-hook relay fan-out.

Hermes strips inherited credentials before child processes start

Hermes proposes removing the BWS token and every password-shaped variable from child-process environments, backed by a campaign inventory of process launch sites. A related gateway patch also addresses file-descriptor…

Paperclip isolates Codex accounts at the gateway boundary

Paperclip proposes isolated multi-account Codex authentication, resolves per-user connection grants at gateway execution and adds device-login building blocks without leaking callback secrets. The three records move…

ZeroClaw adds DAG execution before it adds a stop button

ZeroClaw proposes sequential and parallel DAG plan execution while operators report that running SOP jobs have no cancellation path and a global concurrency ceiling silently overrides per-SOP limits. The cluster exposes…

NanoClaw turns agent templates into versioned plugins

NanoClaw proposes Agent Plugins 1.0.0 directories, explicit single-writer file surfaces and clearer package limits for its hardened image. Together the records turn customization from copied templates into…

PicoClaw finds configuration that the runtime does not honor

PicoClaw operators report that custom shell allow patterns can still fail at execution, configured models can disappear from the list command, and model-specific token limits need a consistent configuration key. The…

IronClaw teaches its agent to stop claiming unverified state

IronClaw proposes suppressing assertions about automation status, extension authorization and recalled memory when the runtime lacks evidence. Related trace work reduces raw logprobs to confidence envelopes, while a…

Hermes narrows the owners of Desktop windows, journals and vaults

Hermes patches three process-boundary leaks: popout windows could attach to the primary profile, aggregate journal writes could block the renderer, and vault tokens could reach argv or inherited environments. The…

IronClaw tests deferred tool search against 1,000-tool catalogs

IronClaw proposes complete bounded signatures and namespace-aware previews for deferred tool discovery, backed by catalog baselines from 100 to 1,000 tools. The work treats discovery output as a model-facing contract,…

Nanobot makes token usage a structured runtime record

Nanobot proposes structured token records and per-iteration diagnostics after an operator reported unexplained token burn. The new records separate model, provider, input, output, cache and reasoning counts so usage can…

OpenClaw writes the authorization contract before multiplayer memory

OpenClaw’s multiplayer-memory design separates private, channel, role, shared, projection and quarantine state, while a companion SDK proposal declares versioned authorization capabilities without claiming enforcement.…

Paperclip brings prior-run knowledge into the heartbeat

Paperclip proposes bounded retrieval of up to five recent same-domain decisions for one assignee, alongside a selected-agent Conference Room and creator-owned question cancellation. The cluster turns prior work and live…

PicoClaw puts one SSRF-safe client under inbound media

Three PicoClaw patches route generic, WeCom and Weixin media downloads through a shared safe HTTP client that rejects private targets. The cluster closes the same server-side request-forgery boundary across channel…

ZeroClaw confines shell state to the agent that owns it

ZeroClaw’s per-agent environment proposal gives each shell a workspace-confined HOME; related work makes skill activation provider-aware and projects each agent’s backend and memory count in the dashboard. The common…

Hermes scopes MCP transports after a wrong-workspace report

A multi-session Hermes gateway could expand MCP workspace variables from the backend default and reuse that process across projects. The proposed fix keys transports, retry state and circuit breakers by canonical…