Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- dist/runner.js:57
- Evidence
execFile(binaryPath, argv, {
Security audit
Security checks across malware telemetry and agentic risk
This plugin appears to be a bounded, read-only Kalshi query bridge with disclosed local CLI and account-data access.
Install this only if you intend to let OpenClaw run your local kalshi CLI for read-only market, order, and portfolio queries. Keep Kalshi private-key material out of tool parameters, approve the optional tool only for agents that should see this data, and prefer hosts satisfying the documented OpenClaw >=2026.7.1-2 requirement.
SkillSpector was not run because this plugin release contains no bundled skills.
61/61 vendors flagged this plugin as clean.
Detected: suspicious.dangerous_exec
execFile(binaryPath, argv, {