Back to plugin

Security audit

McPherson Governance Connector

Security checks for vulnerabilities and agentic risk

Overview

This package is a disclosed OpenClaw governance-visibility connector that observes bounded metadata and does not alter tool execution.

Before installing, understand that this is an observability connector: if you pair and enable it, it will send bounded governance metadata and liveness information to the configured Hosted service. Use the documented disable, killswitch, lock, unpair, and uninstall commands when you want to stop publication or remove it.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
pairing/openclaw-profile-pairing.mjs:70
Evidence
const result = spawnSync(openclawBin, [