Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- index.js:3599
- Evidence
child = spawn(process.execPath, [scriptPath, "--json"], {
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed long-term memory plugin with broad automatic capture and background jobs, but the sensitive behavior matches its stated purpose and is documented with opt-outs and safety gates.
Install only if you want OpenClaw conversations to become durable memory. Review defaults for autoCapture, autoRecall, criticalPush, featureCronSetup.auto, skillMiner.autoApply, Obsidian write settings, and security.allowModelDestructiveMemoryOps before enabling it on shared or sensitive agents.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access
child = spawn(process.execPath, [scriptPath, "--json"], {const r = spawnSync("openclaw", args, { encoding: "utf8", timeout, ...(options.env ? { env: options.env } : {}) });const v = process.env[envVar];