Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- dist/index.js:380
- Evidence
const stdout = execFileSync(
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed wallet-control plugin that can move funds when configured, so it appears purpose-aligned but should only be used with trusted wallet runtimes and explicit user approval.
Install only if you intend to let OpenClaw operate a real wallet. Use previews before payments or trades, verify network, asset, amount, and destination before execution, avoid enabling autonomous approval unless you understand that it covers all wallet write tools until revoked, and configure secrets through the documented encrypted or environment-based paths rather than plaintext config.
Detected: suspicious.dangerous_exec
const stdout = execFileSync(
const stdout = execFileSync(