Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- dist/openclaw-runner.js:17
- Evidence
child = spawn(command, args, { stdio: ["pipe", "pipe", "pipe"], shell: false });
Security audit
Security checks for vulnerabilities and agentic risk
This package handles sensitive local Claude/OpenClaw account credentials, but the behavior is disclosed, user-configured, and aligned with multi-account failover.
Install this only if you want it to manage local Claude/OpenClaw account routing. Prefer secret references over plaintext token files, review setup or Hermes/direct sync dry runs before applying changes, and only enable the watchdog or direct Anthropic route if you want those local config/auth changes managed automatically.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access
child = spawn(command, args, { stdio: ["pipe", "pipe", "pipe"], shell: false });let child = spawn(command, childArgs, {const r = spawnSync(process.execPath, [script], { stdio: "inherit" });const r = spawnSync(process.execPath, [join(__dirname, script), ...args], { stdio: "inherit" });const probe = spawnSync(python, ["-c", probeCode], {const env = { ...process.env };