Skip to main content

Anthropic Extends Claude Code Limits Amid Open-Source Agent Security Flaws

22 AUGUST 2026·2 MIN READ·3 SOURCES·Official source plus independent coverage

Anthropic has prolonged its usage boost for Claude Code as developers experiment with local alternatives like OpenClaw, which faces critical new security vulnerabilities.

Anthropic Extends Claude Code Limits Amid Open-Source Agent Security Flaws

Key takeaways · 3

  • 01

    Anthropic extended its temporary 50% usage limit boost for Claude Code to August 31.

  • 02

    Critical OpenClaw vulnerabilities enable sandbox escapes and credential theft across thousands of public instances.

  • 03

    Developers are evaluating local orchestration tools like LangGraph and Goose to run local agent models.

Claude Code Limits Extended

Anthropic has extended a temporary 50% usage limit boost for Claude Code until August 31. [5] The company announced that it hopes to make this change permanent. [5] This marks the fourth time Anthropic has extended the deadline for this promotion since it began in May. [5]

Claude Pro costs $20 a month, or $17 a month if users pay for a year up front. [3] On the free plan, a session limit resets every five hours. [3] The Claude Code lead noted this expanded access supports emerging AI-era organizational roles, particularly for high-volume "prototypers" and "builders." [1] Additionally, developers can use Claude Code with their Pro or Max subscription plans. [2]

Security Risks in OpenClaw

Vulnerabilities in the OpenClaw agent framework include CVE-2026-44112, which carries a CVSS score of 9.6. [4] These vulnerabilities can allow attackers to escape the agent sandbox, steal credentials, and elevate privileges. [4]

Reports indicate there are approximately 245,000 public instances of OpenClaw. [4] In addition, 335 malicious skills were found in the official ClawHub marketplace, representing about 12% of the registry. [4] Researchers warn that these sandbox escape vectors can bypass standard container protections during local deployments. [4] Security reports indicate that OpenClaw's official marketplace contained hundreds of malicious skills, contributing to a high-risk environment for deploying local agents. [4]

Local Agent Testing

Developers are testing local orchestration tools like LangGraph, CrewAI, and Goose alongside models such as qwen3:8b. [4] In one test using a local qwen3:8b model, a LangGraph agent correctly calculated the total price of apples and grapes in 64.1 seconds. [4]

A Goose agent interacting with the same model successfully executed a shell command to count Python files. [4] The testing environment utilized Ollama to serve the models, proving that developers can bypass cloud APIs entirely for basic tasks. [4] However, execution speed remains heavily dependent on hardware capabilities, forcing teams to balance subscription savings against local latency. [4]

What it means

The push toward local AI agents is accelerating as developers look for alternatives to cloud-based subscriptions like Claude Pro. Anthropic's repeated extensions of usage limits suggest pressure to retain developers testing Claude Code against local orchestration tools like LangGraph and Goose. However, the critical vulnerabilities found in OpenClaw demonstrate that giving local agents deep system access carries massive security risks. What the sources don't address: How Anthropic plans to structure its permanent pricing tiers if the 50% limit boost becomes the new baseline.

The transition to agentic workflows is splitting between cloud-based tools and local alternatives. As platforms like Anthropic extend limits to capture market share, developers adopting open-source agents must rigorously vet their security posture.

Why it matters
Daily session

Turn this story into practical AI skill after launch.

Get the release link for daily sessions built around your role and industry.

Join the waitlist

How this developed

  1. 22 August 2026

    Anthropic Extends Claude Code Limits Amid Open-Source Agent Security Flaws

  2. 22 August 2026

    Event evidence refreshed from source cluster.

  3. 22 August 2026

    Event evidence refreshed from source cluster.

  4. 29 June 2026

    Event created from source cluster.

Sources

AI fluency, one session a day, built for your work.