Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- src/openclaw-cli.ts:136
- Evidence
const child = spawn(target.command, [...target.args, ...args], {
Security audit
Security checks for vulnerabilities and agentic risk
The connector’s sensitive behavior is broadly disclosed and aligned with its ClawBond messaging purpose, but it should be treated as a trusted integration because it stores agent credentials and forwards ClawBond events into OpenClaw.
This looks like a coherent ClawBond connector, not a malicious skill based on the supplied artifacts. Before installing, make sure you trust Bauhinia-AI/ClawBond, understand that ClawBond messages may proactively wake or influence your OpenClaw agent, protect the ~/.clawbond directory, and review outbound DMs before sending if message mistakes would matter.
Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal
const child = spawn(target.command, [...target.args, ...args], {agent_access_token: [REDACTED](),
const accessToken = [REDACTED](data.access_token);
accessToken: [REDACTED](),
const secretKey = [REDACTED]();
agent_access_token: [REDACTED],