Back to plugin

Security audit

OpenShell Sandbox

Security checks for vulnerabilities and agentic risk

Overview

This package coherently implements an OpenShell sandbox backend for OpenClaw, with high-impact workspace mirroring and SSH execution that are disclosed and purpose-aligned.

Install this only if you want OpenClaw Gateway to use OpenShell for agent sandboxes. Verify the configured openshell command, gateway, workspace, providers, and policy path, because the plugin can create/delete OpenShell sandboxes, run SSH commands in them, and synchronize workspace files between the Gateway host and the remote sandbox.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.