Agent skill

Update Openclaw

by heypinchy in heypinchy/pinchy

A skill your agent uses when bumping the pinned OpenClaw core version (openclaw npm package), when preparing a Pinchy release, or when the user asks to "update OpenClaw" / "upgrade OpenClaw" / check…

AGPL-3.0Auto-check passedDevOps & Cloud

Install Update Openclaw

skills CLI
$ npx skills add heypinchy/pinchy --skill update-openclaw -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install heypinchy/pinchy update-openclaw --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/heypinchy/pinchy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/update-openclaw .claude/skills/update-openclaw && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
update-openclaw
GitHub stars
182
Token cost
~2.8k tokens
SKILL.md length
1,322 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
AGPL-3.0

At a glance

A skill your agent uses when bumping the pinned OpenClaw core version (openclaw npm package), when preparing a Pinchy release, or when the user asks to "update OpenClaw" / "upgrade OpenClaw" / check…

  • Works in 2 steps: Check current vs. latest. → **Read every release's notes between…
  • Bumping the pinned OpenClaw core version (openclaw npm package)
  • SKILL.md covers Overview, Procedure and If a release note flags…
  • Calls pnpm, npm and gh

What it does

Update Openclaw is an agent skill from heypinchy/pinchy. Use when bumping the pinned OpenClaw core version (openclaw npm package), when preparing a Pinchy release, or when the user asks to "update OpenClaw" / "upgrade OpenClaw" / check for a newer OpenClaw version.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with npm. The repository describes itself as: Self-hosted AI agent platform built on OpenClaw. Enterprise-ready, offline-capable, open source. 🦞. The licence is AGPL-3.0.

When your agent uses it

  • Bumping the pinned OpenClaw core version (openclaw npm package)
  • Preparing a Pinchy release
  • The user asks to update OpenClaw / upgrade OpenClaw / check for a newer OpenClaw version

Example prompts

  • “update OpenClaw”
  • “upgrade OpenClaw”
  • “/update-openclaw”

Requirements

  • Node.js
  • Docker

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Check current vs. latest.
  2. **Read every release's notes between current (exclusive) and target

What it can do on your machine

Read from SKILL.md and the folder at commit 5159959. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • npm
    • gh
    • git
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, npm, gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Update Openclaw loads about 2.8k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 1,322 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from heypinchy/pinchy at commit 5159959, republished under its AGPL-3.0 licence (© heypinchy). 1,322 words, ~2,791 tokens.

Download SKILL.mdSave it as .claude/skills/update-openclaw/SKILL.md (or your agent's skills folder).
name
update-openclaw
description
Use when bumping the pinned OpenClaw core version (openclaw npm package), when preparing a Pinchy release, or when the user asks to "update OpenClaw" / "upgrade OpenClaw" / check for a newer OpenClaw version.

Update the pinned OpenClaw version

Overview

Pinchy pins the OpenClaw core runtime version in two places that a drift guard keeps in lockstep:

  • packages/web/package.json → dependencies.openclaw
  • Dockerfile.openclaw → RUN npm install -g openclaw@<version>

packages/web/src/__tests__/lib/openclaw-version-pin-drift.test.ts greps Dockerfile.openclaw for the literal npm install -g openclaw@ line and fails if it doesn't match package.json. Both places also feed /api/version.

Core principle: OpenClaw upgrades have repeatedly broken Pinchy in ways pnpm test/tsc don't catch, because the breakage is in runtime protocol behavior (session keys, tools.allow semantics, config.apply timing, plugin manifest resolution) — see the reference_oc_* / reference_openclaw_* memory entries about past compatibility cliffs. Never treat "npm view shows a newer version" as a green light by itself. Read the release notes for every version between current and target first.

Procedure

  1. Check current vs. latest.

    bash
    grep openclaw packages/web/package.json
    npm view openclaw version
    npm view openclaw versions --json | tail -20   # see every point release in between
  2. Read every release's notes between current (exclusive) and target (inclusive) — not just the target's diff summary, since intermediate point releases can carry changes too:

    bash
    gh release list --repo openclaw/openclaw --limit 20
    gh release view v<version> --repo openclaw/openclaw

    Read the full text, not just headline "Highlights" — the "Additional ... fixes" subsections often contain the entry that actually matters to us. Work through it against these four questions, in this order, and write down what you find for each before moving to step 3:

    a. Incompatibility risk. Anything touching session keys, tools.allow semantics, config.apply timing, plugin config/manifest resolution, or provider baseUrl handling — the areas that have bitten us before (see reference_oc_* / reference_openclaw_* memory entries). Look at sections titled "Sessions", "Gateway, Security, and Trust", "Plugins and Packaging", and any breaking/migration language anywhere else. Watch especially for new gateway-startup / config self-healing behavior — these don't show up in pnpm test/tsc at all and only fail in the docker E2Es. The agent:bootstrap hook contract is one of these silent dependencies. config/pinchy-hooks/bootstrap-memory-group-filter/ (the #369 leak fix) assumes the event carries context.bootstrapFiles (array) and context.sessionKey (string), that reassigning context.bootstrapFiles is read back by the caller, and that internal hooks load via native import(). If the notes touch bootstrap/hook events, session-key shape, or the internal hook loader, verify against the installed dist that these still hold — the hook now console.warns instead of failing open, so also check the gateway logs on the staging deploy for that warning. A silent contract change here re-opens a P0 eu-ai-act memory leak. See the hook's HOOK.md Verification section for the exact staging check. Real example the 2026.6.11 bump tripped: OpenClaw 2026.6.x added startup config auto-restore — on a size-drop / missing-meta vs last-known-good it restores openclaw.json.last-good over openclaw.json at gateway start (recoverConfigFromLastKnownGood). This broke the setup-wizard reset (it deleted openclaw.json but not the backups, so OC restored the prior test's config referencing wiped secrets → crash-loop). If notes mention config backup / last-known-good / recovery / restore, expect the setup-wizard + integration E2Es to need reset-choreography updates.

    b. Resolved issues we have workarounds for. Grep our own code for the upstream issue/PR numbers and version-guard comments before reading notes:

    bash
    git grep -rniE "openclaw/openclaw#[0-9]+|openclaw issue|version.?guard|workaround|TODO\(#" -- packages/ config/ | grep -vi node_modules

    For each hit, check the upstream issue state (gh issue view <n> --repo openclaw/openclaw --json state,closedAt). But "issue closed" is necessary, not sufficient — a closed issue is where naive audits go wrong. Before removing any workaround, confirm ALL of:

    1. The fix shipped in a release ≤ our target pin. Close date ≠ release date, and release notes often don't name the issue. When in doubt, inspect the actually-installed bundle in node_modules/.pnpm/openclaw@<target>/node_modules/openclaw/dist for the fixed code, not just the changelog.
    2. The fix targets OUR code path, not a sibling. Real example: openclaw #75534 (config.apply no-op restart, tracked on our side by #215) fixed OpenClaw's own writeConfigFile short-circuit — but Pinchy writes the config file itself and then calls config.apply, a different path whose env.*→default-restart mechanism was still present verbatim in 2026.6.11. Issue closed, workaround NOT removable.
    3. The workaround is actually a bug-workaround, not a defensive error-UX classifier or an architectural decoupling that stays valuable after the bug is fixed. Real examples that are NOT removable-on-close: the thought_signature error classifier (model-error-classifier.ts, #338 — renders graceful UX whenever the upstream error surfaces, and its removal is gated on an empirical live-path condition, not the issue state), and the Telegram store-based allowFrom (#47458 — a restart-avoiding design choice, see reference_ollama_local_rewrite_decoupling.md for the "decoupling, not a version workaround" pattern).
    4. Prefer the tracking issue's own stated verification (e.g. "remove X, run E2E agent-create-no-restart.spec.ts, confirm it stays green") over bundle archaeology. Bundle-reading can prove a workaround is STILL needed (mechanism present) but is weak evidence that one is safe to REMOVE — that needs the prescribed test. Memory: reference_config_apply_rate_limit_drop.md warns version guards can become bugs after an upstream fix, so this cuts both ways.

    If all four hold, remove the workaround in the same change with a test proving native behavior now covers it. Otherwise leave it and record why.

    c. Features we built ourselves that OpenClaw now does natively. Scan for "native", new config keys, or new built-in capabilities in areas where Pinchy has a bespoke plugin or workaround (e.g. transcript capture, session identity, memory, approvals — see reference_pinchy_owned_transcript.md, reference_openclaw_approval_primitives.md, reference_mcp_native_credential_proxy.md for precedent: MCP was migrated from a Pinchy-built plugin to native mcp.servers + a thin credential proxy once OpenClaw grew native support). Same feature name ≠ same scope — check whether the native capability covers the REASON we built the bespoke version, not just its surface. Real example: 2026.6.10 added a native "session-transcript SDK" (read, append, publish, lock), which sounds like it could replace pinchy-transcript. But its methods are all keyed by { agentId, sessionKey, sessionId } — session-scoped. Pinchy owns channel_messages precisely because it needs a channel-lifetime record that survives /new/reset/compaction (per PR #553 / reference_pinchy_owned_transcript.md); adopting the session-scoped SDK would reintroduce the exact blank-on-/new bug it fixed. So: not adoptable. If a native capability genuinely covers the reason, flag it as a follow-up simplification; if it only matches the name, record why it doesn't fit so the next bump doesn't re-litigate it.

    d. New OpenClaw features worth exposing in Pinchy. Anything new that fits Pinchy's enterprise-governance angle (permissions, audit, channels, models) or that Pinchy's target audience (self-hosted enterprise teams, see "Product Context" in AGENTS.md) would plausibly want surfaced in the UI/API. Note these separately as feature ideas — they are out of scope for the bump itself, not blockers.

  3. Summarize findings against the four questions before touching code. If (a) is empty, treat the bump as safe to proceed. If (a) is non-empty, flag it to the user before proceeding — don't silently absorb a breaking change into a routine bump. (b), (c), and (d) don't block the bump, but report them: (b) as follow-up cleanup candidates (ideally done alongside the bump if small), (c)/(d) as things worth a tracked issue or a spawn_task-style follow-up rather than silently doing nothing with them.

  4. Bump both pinned locations to the same target version:

    • packages/web/package.json → dependencies.openclaw
    • Dockerfile.openclaw → the npm install -g openclaw@... line
  5. Check openclaw-node (packages/web/package.json → dependencies["openclaw-node"], our own client library in ~/projects/openclaw-node/) for a matching newer release too — npm view openclaw-node version. If it needs a release and we own it: openclaw-node has NO pnpm release script (that's Pinchy's mechanism). Its actual release flow (v0.13.0/v0.13.1 precedent): add a CHANGELOG entry, bump package.json, commit chore: release vX.Y.Z on main, wait for CI on that commit, then gh release create vX.Y.Z — the GitHub release triggers publish.yml, which re-verifies CI and publishes to npm. Verify with npm view openclaw-node version before bumping the Pinchy pin.

  6. Install and verify:

    bash
    pnpm install
    pnpm -C packages/web vitest run src/__tests__/lib/openclaw-version-pin-drift.test.ts
    node --test config/__tests__/bootstrap-memory-group-filter.test.mjs  # #369 hook contract
    pnpm test
    pnpm build

    Note: the hook test above proves the filter logic, not that OpenClaw still fires the hook. If the notes touched bootstrap/hook/session-key behavior, run the HOOK.md staging check before shipping.

  7. Don't commit automatically. Report the diff (git status --short, git diff --stat) and let the user decide to commit/PR — this touches a runtime dependency, not just app code.

Show full SKILL.md (69 more words)Show less

If a release note flags something sensitive

Don't just bump anyway. Options, in order of preference:

  • Pin to the last version before the risky change and note why in a commit message / to the user.
  • Do the bump on a branch, add/adjust a regression test for the specific behavior the release note describes, then bump.
  • Ask the user whether to proceed if the tradeoff isn't yours to make alone.

© heypinchy, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/update-openclaw of heypinchy/pinchy.

Open the folder on GitHubat commit 5159959

Compare with similar skills

Update Openclaw next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Update Openclaw compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Update Openclaw this skillheypinchy/pinchy182—~2.8kAutomated safety check: PassAGPL-3.0
OmniRoute Backup and Sync CLIdiegosouzapw/OmniRoute74k—~948Automated safety check: PassMIT
Repo Hygiene Scan and FixQwenLM/qwen-code28k—~1.7kAutomated safety check: PassApache-2.0
Thesvgglincker/thesvg2.8k—~1.5kAutomated safety check: PassMIT
Reflexo ReleaseMyriad-Dreamin/typst.ts1.2k—~1.5kAutomated safety check: PassApache-2.0
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • OmniRoute Backup and Sync CLI

    diegosouzapw/OmniRoute

    Backup and restore OmniRoute data from the CLI. Trigger incremental snapshots, sync to cloud storage, manage backup schedules, and restore from archive files.

    74k GitHub stars~948 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.

    28k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Reflexo Release

    Myriad-Dreamin/typst.ts

    Guide Reflexo/typst.ts release preparation and operator handoffs.

    1.2k GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed

More from heypinchy/pinchy

All 18 skills in this repo
  • Knowledge Search

    heypinchy/pinchy

    Answer questions from the organization's indexed documents using knowledgesearch, and cite every claim back to a retrieved passage.

    182 GitHub stars~1.4k tokensUpdated 18 days ago
    Auto-check passed
  • Odoo Read

    heypinchy/pinchy

    Query and summarize data from a connected Odoo instance with the odoo read tools (describe, count, read, aggregate).

    182 GitHub stars~965 tokensUpdated 18 days ago
    Auto-check passed
  • Review Docs

    heypinchy/pinchy

    Use before opening a PR that changes docs/ or a user-visible surface (an API route, the tool registry, an agent template, the audit event catalogue, the settings navigation, plugin tools), and when…

    182 GitHub stars~1.3k tokensUpdated 18 days ago
    Auto-check passed
  • Update Dependencies

    heypinchy/pinchy

    A skill your agent uses when bumping general npm/pnpm dependencies across the Pinchy workspace (root, packages/web, packages/plugins/, docs), when the user asks to "update dependencies," "check for…

    182 GitHub stars~1.5k tokensUpdated 18 days ago
    Auto-check passed
  • A skill your agent uses when a new Ollama Cloud model is announced or available (e.g.

    182 GitHub stars~3.9k tokensUpdated 18 days ago
    Auto-check: notes
  • Cut Pinchy Release

    heypinchy/pinchy

    A skill your agent uses when cutting, tagging, or publishing a new Pinchy version — e.g.

    182 GitHub stars~11k tokensUpdated 18 days ago
    Auto-check: notes

Works with

Categories

Questions about Update Openclaw

What does Update Openclaw do?

A skill your agent uses when bumping the pinned OpenClaw core version (openclaw npm package), when preparing a Pinchy release, or when the user asks to "update OpenClaw" / "upgrade OpenClaw" / check…. Update Openclaw is an agent skill from heypinchy/pinchy. Use when bumping the pinned OpenClaw core version (openclaw npm package), when preparing a Pinchy release, or when the user asks to "update OpenClaw" / "upgrade OpenClaw" / check for a newer OpenClaw version.

When should I use Update Openclaw?

Update Openclaw fits situations like: bumping the pinned OpenClaw core version (openclaw npm package); preparing a Pinchy release; the user asks to update OpenClaw / upgrade OpenClaw / check for a newer OpenClaw version.

How do I install Update Openclaw in Claude Code?

Run `npx skills add heypinchy/pinchy --skill update-openclaw -a claude-code`. Or copy the skill folder (.claude/skills/update-openclaw in heypinchy/pinchy) into .claude/skills/update-openclaw in your project. Claude Code loads it when a task matches its description.

How do I install Update Openclaw in Codex?

Run `npx skills add heypinchy/pinchy --skill update-openclaw -a codex`. Or copy the skill folder (.claude/skills/update-openclaw in heypinchy/pinchy) into .agents/skills/update-openclaw in your project. Codex loads it when a task matches its description.

Can I use Update Openclaw in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add heypinchy/pinchy --skill update-openclaw -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/update-openclaw, .gemini/skills/update-openclaw, .github/skills/update-openclaw and .opencode/skills/update-openclaw in your project.

What does Update Openclaw need to run?

Going by SKILL.md and its folder, Update Openclaw needs the command-line tools its instructions call (pnpm, npm, gh, git and node). Our summary lists: Node.js; Docker.

Does Update Openclaw access the network?

SKILL.md contains no URLs. Its commands use npm, gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Update Openclaw safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Update Openclaw use?

Update Openclaw is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Update Openclaw use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Update Openclaw?

Skills that share tags, products or a category with Update Openclaw: OmniRoute Backup and Sync CLI (diegosouzapw/OmniRoute, 74k stars), Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars), Thesvg (glincker/thesvg, 2.8k stars) and Reflexo Release (Myriad-Dreamin/typst.ts, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Update Openclaw?

heypinchy (a GitHub organization) maintains it in heypinchy/pinchy, which has 182 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on September 21, 2026.

Source: heypinchy/pinchy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.