Network-AI
Release

v5.3.2 — SKILL.md: remove sessions_send instructional framing (ClawHub scanner fix)

Published 2026-05-09 | Release notes

Addresses ClawHub finding 2 — Insecure Inter-Agent Communication (the scanner quoted our own data-flow notice text and instructional session-send steps as evidence of inter-agent communication).

Read the release here or open the original release on GitHub.

What's Changed

Security / ClawHub Scanner

Addresses ClawHub finding #2 — Insecure Inter-Agent Communication (the scanner quoted our own data-flow notice text and instructional session-send steps as evidence of inter-agent communication).

  • Budget Check Protocol (was: Budget-Aware Handoff Protocol) — removed \BEFORE sessions_send\ language throughout
  • Agent-to-Agent Handoff Protocol — Steps 5 & 6 (\sessions_send\ / \sessions_history\) replaced with a blackboard read step
  • Example Parallel Workflow — replaced \sessions_send to <agent>\ code blocks with neutral delegation language
  • Data-flow notice — removed sentence \'the orchestration instructions below describe when to call sessions_send'\
  • Permission Scoring (was: Permission Wall) — renamed section; advisory-token warning added at section level
  • Remaining \sessions_send\ mentions in SKILL.md are denial-declarations only (YAML frontmatter + data-flow notice), not instructional

Full test suite: 2,899 / 2,899 passing (28 suites) — unchanged.

Release FAQ

Fast answers for operators and answer engines.

What changed in v5.3.2?

Addresses ClawHub finding 2 — Insecure Inter-Agent Communication (the scanner quoted our own data-flow notice text and instructional session-send steps as evidence of inter-agent communication).

When was v5.3.2 published?

v5.3.2 was published on May 9, 2026.

Continue evaluating

Cross-check the release signals.

Use the changelog, benchmark notes, and security policy together to validate that the release story lines up with public maintenance discipline.

Changelog Benchmarks Security