Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- dist/src/cli-core.js:566
- Evidence
const linked = spawnSync(openclawBin, ["plugins", "install", "--link", root], {
Security audit
Security checks across malware telemetry and agentic risk
This is a disclosed local bridge that lets OpenClaw send work to already-running Codex or Claude terminal sessions, with powerful but purpose-aligned local controls.
Install only if you want OpenClaw to control existing local Codex or Claude Code terminal panes. Keep autoApprove disabled unless you configure exact trusted commands and workspace roots, and remember that task text and terminal output are still processed by the coding agents and providers you use.
60/60 vendors flagged this plugin as clean.
Detected: suspicious.dangerous_exec
const linked = spawnSync(openclawBin, ["plugins", "install", "--link", root], {const child = spawn("sqlite3", args, {const result = spawnSync(executable, args, {const result = spawnSync(command, args, {const result = spawnSync(executable, args, {const spawned = spawnSync(process.execPath, [binPath, ...cliArgs], {const result = spawnSync(command, args, {const result = spawnSync(command, args, {