Automated harness-observability audit found a gap for openclaw.
- Harness exposes: Sessions can be explicitly published as a revocable read-only public link, exposing both existing and future conversation text to anyone with the link.
- ClawMetry misses: Session dataclass has no field for share/publish state (e.g. is_shared, share_url, revoked_at), and the adapter does not read any share-registry file. This is a real security/exposure signal (an agent transcript being publicly link-accessible) that ClawMetry's Guard/security posture surfaces have no visibility into.
- Where (harness):
CHANGELOG.md 2026.9.3 highlights (#139489)
- Severity: high
- Closest capability: new
Filed by scripts/harness/audit.py. Fingerprint: hgap-b04a00b71e (used to dedupe — keep it in the body).
Automated harness-observability audit found a gap for openclaw.
CHANGELOG.md 2026.9.3 highlights (#139489)Filed by
scripts/harness/audit.py. Fingerprint: hgap-b04a00b71e (used to dedupe — keep it in the body).