Back to plugin

Security audit

ONNX

Security checks for vulnerabilities and agentic risk

Overview

This package coherently provides local ONNX decision-model inference for OpenClaw, with model downloads and local worker behavior disclosed and bounded.

Install only if you want OpenClaw to run local ONNX decision models. Expect CPU, memory, disk, and optional native dependency requirements; model downloads are large but pinned and hash-verified, and inference data stays local according to the inspected code.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/.setup/worker-client-BfBezMH8.mjs:234
Evidence
const child = spawn(process.execPath, resolveRuntimeWorkerArgv(this.workerUrl), {