Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- scripts/bump-openclaw.mjs:52
- Evidence
const result = spawnSync(cmd, args, {
Security audit
Security checks across malware telemetry and agentic risk
The package is a coherent Apify web-scraping plugin that uses an Apify API key for user-directed scraping, with some setup caveats but no artifact-backed malicious behavior.
Install only if you want agents to run Apify Actors on your behalf. Treat the Apify API key as sensitive, monitor Apify usage and costs, avoid custom base URLs, and review Actor inputs before starting broad social, lead-generation, or contact-info scraping jobs.
SkillSpector was not run because this plugin release contains no bundled skills.
61/61 vendors flagged this plugin as clean.
Detected: suspicious.dangerous_exec
const result = spawnSync(cmd, args, {const result = spawnSync(cmd, args, {