Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- node_modules/baileys/lib/Utils/messages-media.js:88
- Evidence
exec(cmd, err => {
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent WhatsApp channel plugin that discloses its WhatsApp login, messaging, media, history/search helper, and optional call capabilities.
Install only if you want OpenClaw connected to a WhatsApp account. Use a separate WhatsApp number if possible, keep allowlists and pairing policies tight, and only enable wacli history sync, plugin message hooks, or voice calls when you understand that they expose private WhatsApp content or use a separate linked-device session.
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.exposed_secret_literal
exec(cmd, err => {return execSync(`node ${join(__dirname, 'runbench')} ${type} -q`)const benchmark = spawn(
const { stderr } = await execFile('npx', ['pkg', filePath, '--config', configPath], { shell: true })const child = spawnSync(process.execPath, [
const { stderr } = await exec(`npx pkg ${filePath} --config ${configPath}`)new Function('module', 'return import(module)')('./esm.mjs').catch((err) => {eval(`
const realImport = new Function('modulePath', 'return import(modulePath)')password: '[REDACTED]'
authorization: '[REDACTED]'