What's in 3.1.1
Hook API content sanitization — /hooks/receive now sanitizes the content param with wp_kses_post() so allowed HTML (headings, links, bold) is preserved when OpenClaw pushes ability requests. Other params still use sanitize_text_field().
Dependency bump — simple-git 3.30.0 → 3.33.0 via npm overrides.
See CHANGELOG.md for full details.