Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- dist/index.js:789
- Evidence
const child = spawn("bash", [scriptPath, ...args], {
Security audit
Security checks for vulnerabilities and agentic risk
The package is a coherent IdentyClaw identity and wallet plugin with sensitive but disclosed credential, API-login, and optional wallet capabilities.
Install only if you intend to let OpenClaw use IdentyClaw Passport credentials. Keep private keys out of chat/config where possible, restrict tools.allow carefully, and enable idcp only when you want the agent to perform NEAR/RODiT wallet actions such as funding, transfers, rotation, or activation.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access
const child = spawn("bash", [scriptPath, ...args], {const result = spawnSync(process.execPath, [script, defaultDir], {if (process.env[envName] !== undefined) {