Back to plugin

Security audit

Code Agent

Security checks for vulnerabilities and agentic risk

Overview

This is a high-trust coding-agent plugin, but its repository-changing and background-session behavior is disclosed and guarded by plan and worktree controls.

Install only if you want OpenClaw to launch local coding agents that can run commands and modify repositories. Review the Codex sandbox/approval settings, keep plan approval and worktree decision controls enabled for important repos, and disable autoUpdate if you do not want daily update checks and button-based self-updates.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description includes broad natural-language trigger phrases like "let oca do...", "ask oca to...", and "have oca handle...", which can cause overly eager invocation from ordinary user phrasing rather than an explicit, high-signal command. In an orchestration skill that can launch and continue coding-agent sessions, this increases the chance of unintended delegation of repository-affecting actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.