Self-hosted open-source agent that runs skills, cron jobs, browsers and native apps on any OS
Koda Score = weighted blend: capability 35, ease 20, value 25, momentum 20.
Capability is high because it spans messaging, memory, cron automation, browser and native app control across six platforms with a 17,000-plus skill registry; ease is middling because even the guided installer cannot hide that a clean reinstall and permission re-audit is the recommended path and users report the process got more complicated; value is strong since the core is open source and self-hosted; momentum is near the top given 389k stars, 81.6k forks, 89 repos and a release the community calls its largest ever.
10 MIN READVersion 2026.8.1, the release the project itself calls OpenClaw 2.0, rewrites installation, the web app, memory, skills, model setup, automation, browser and app control, plugins and the security model in one go, and upgrading in place is where people are getting burned: a GitHub discussion already reports exec and file access failing to restore after the update. Treat it as a fresh install, read the security notes before anything else, and rebuild your skills with a hard look at what each one can reach. Do that and you get the broadest open agent stack on the market, 389k GitHub stars deep, for the price of your own hardware and model tokens; skip it and you are running an agent with elevated permissions that reads untrusted web pages and messages, which the Reddit and Register coverage is right to worry about.
The largest release in OpenClaw's history is worth installing, provided you delete the old one first and hand back permissions one skill at a time.

OpenClaw 2.0 (v2026.8.1) touches every layer of the app, so wipe the old install and start clean instead of patching over it.
The new guided installer detects Codex, ChatGPT, Claude, Ollama and LM Studio and version-checks the model before saving, which fixes the old setup pain if you let it run from scratch.
Users on GitHub report exec and file permissions not restoring after upgrade; re-enable each skill deliberately and confirm what it can touch in your browser and apps.
Security is the live debate: the agent processes web pages and messages with elevated permissions, and hidden instructions in that content are the attack path critics keep pointing at.
Reaction is loud but shallow so far: launch buzz on Hacker News and Product Hunt about the easier install and rebuilt browser app, running straight into pointed security criticism from Reddit and The Register and reports of broken permissions after upgrading.
This is the largest update in OpenClaw's history, simplifying installation and rebuilding the browser app.
PraiseSecurity is worse than expected: messages and web pages the agent processes can carry hidden instructions, and it handles that content with elevated permissions.
CritiqueAfter the update the tool permissions did not fully restore; exec and file access had to be re-enabled from the config or by restarting the environment.
MixedAfter six weeks of testing, it is a self-hosted agent that runs on cron, connects to over 17,000 skills and manages workflows around the clock.
PraiseThe agent processes web pages and messages with elevated permissions, so hidden instructions in untrusted content are a real attack path, and even the 2.0 security pass draws a dumpster-fire verdict from The Register.
Upgrading in place has broken tool permissions for some users, with exec and file access failing to restore, which is why a clean reinstall is the recommended route.
Initial setup is complex and users say the security-hardened install is more complicated than before, despite the new guided installer.
Offline capability is limited; most useful model paths still route through hosted providers unless you run Ollama or LM Studio locally.
The main repo carries 3,746 open issues and 2,507 open pull requests, so expect rough edges and a fast-moving target rather than a polished product.
Read the v2026.8.1 release notes and security changes, note the skills and plugins you rely on, then uninstall the old version completely rather than patching it.
Run the guided installer, let model detection find your Codex, ChatGPT, Claude, Ollama or LM Studio setup, and confirm the version check passes before saving.
Re-add skills one at a time, checking what each can reach in exec, files, browser and native apps, and schedule cron automations only after each skill is verified.
Rebuild from zero, audit every skill's reach, and OpenClaw 2.0 is the most capable free agent runtime a builder can own right now. Upgrade in place and you inherit both the old permission sprawl and the new breakage.
Field research: 1 page scraped · 3 search passes · 24 community sources. Reviewed by the Koda desk on 2026-09-04.
The Lab lands in the morning brief. Unsubscribe anytime.