Back to plugin

Security audit

multi-clawd

Security checks for vulnerabilities and agentic risk

Overview

This package handles sensitive local Claude/OpenClaw account credentials, but the behavior is disclosed, user-configured, and aligned with multi-account failover.

Install this only if you want it to manage local Claude/OpenClaw account routing. Prefer secret references over plaintext token files, review setup or Hermes/direct sync dry runs before applying changes, and only enable the watchdog or direct Anthropic route if you want those local config/auth changes managed automatically.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/openclaw-runner.js:17
Evidence
child = spawn(command, args, { stdio: ["pipe", "pipe", "pipe"], shell: false });

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/shim.js:106
Evidence
let child = spawn(command, childArgs, {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/watchdog-schedule.js:112
Evidence
const r = spawnSync(process.execPath, [script], { stdio: "inherit" });

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/cli.mjs:84
Evidence
const r = spawnSync(process.execPath, [join(__dirname, script), ...args], { stdio: "inherit" });

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/hermes.mjs:181
Evidence
const probe = spawnSync(python, ["-c", probeCode], {

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/cli.mjs:870
Evidence
const env = { ...process.env };