Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- packages/openclaw-live-observer/index.mjs:504
- Evidence
return spawnSync(executable, args, {
Security audit
Security checks across malware telemetry and agentic risk
This package is a disclosed local governance-diagnostics and shadow-observation connector, with sensitive local profile access that is scoped and purpose-aligned.
Install only if you want an OpenClaw profile-level governance diagnostics connector. Leave remote shadow disabled unless you understand the configured HTTPS endpoint and per-tool metadata, and treat the local binding, receipt directory, and device/operator credential state as private operational data.
SkillSpector was not run because this plugin release contains no bundled skills.
60/60 vendors flagged this plugin as clean.
Detected: suspicious.dangerous_exec
return spawnSync(executable, args, {