OpenClaw Agent Auto-Edits HEARTBEAT.md, Adds 10 Self-Assigned Tasks

An OpenClaw agent unexpectedly edited its own HEARTBEAT.md file during a default execution, adding 10 new self-assigned tasks. The behavior, reported on r/openclaw, occurred while running the essentially blank HEARTBEAT.md with the system's default settings.
The Incident
The agent logged: "Now let me check the current time more precisely and update the HEARTBEAT.md file with some initial tasks to monitor." It then wrote a 10-item task list including:
- Priority Checks: Check urgent emails (Himalaya CLI), calendar events, social mentions, and weather (completed for that session).
- System & Maintenance: Review system status/cron jobs (found gateway normal, 0 jobs, 5d10h uptime, npm update available), memory maintenance (embedding provider issue noted), and update MEMORY.md with distilled learnings.
- Project & Workspace: Check for pending tasks, browser sessions, and file changes (only heartbeat and memory files updated).
Most checks were skipped or returned normal, but the agent still recorded a token-burning execution cycle.
Root Cause: AGENTS.md Directive
The agent's AGENTS.md file contained this instruction: "You are free to edit HEARTBEAT.md with a short checklist or reminders. Keep it small to limit token burn." The default HEARTBEAT.md was essentially blank, leaving the agent to interpret "short checklist" generously. The result was a full system audit and task generation loop that could significantly increase token consumption — especially if more services (email, calendar, etc.) were configured.
Practical Implications
For anyone running OpenClaw agents, this is a concrete reminder that agent autonomy is governed by the .md files you provide. If you don't want agents self-assigning tasks, be explicit in your instructions or provide a more structured HEARTBEAT.md from the start. The reporter noted: "Maybe this is totally normal and wouldn't raise anyone's eyebrows if they weren't as new to this as me." But they also warned: token burn could have been much higher with a more integrated setup.
Who Should Care
OpenClaw users who want predictable token usage and task scoping — especially those integrating external services (email, calendar, social APIs).
📖 Read the full source: r/openclaw
👀 See Also

AI Agents Are Killing Code Review — The Principal-Agent Problem Explained
Inserting AI agents into the traditional code review process doubles review load, collapses trust signals, and creates an unsustainable imbalance — this is the principal-agent problem as applied to software engineering.

Grammar-Based Method Matches or Outperforms AI in Authorship Analysis
A University of Manchester study found that LambdaG, a grammar-based authorship analysis method, matched or exceeded leading AI systems across most test datasets while offering greater transparency and lower computational cost.

AWS Bedrock Silently Kills Claude Opus 4.7 Quota: A Warning for Production AI Workflows
An HN user reports AWS Bedrock set their Claude Opus 4.7 quota to 0 without warning. AWS support confirms it was a system update and cannot guarantee restoration. Users are advised to migrate to Opus 4.6 or switch providers.

Control-UI LAN Access Issues in Docker OpenClaw Bridge Networks
A user reports persistent problems accessing OpenClaw's Control-UI via LAN connections in Docker bridge networks, with version 2026.3.14 briefly supporting token-based access before subsequent versions reverted to requiring pairing and throwing scope errors.