Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- dist/src/public-access/frpc-manager.js:771
- Evidence
return execFileSync("powershell", [
Security audit
Security checks for vulnerabilities and agentic risk
This mobile OpenClaw plugin appears purpose-aligned, but it grants broad gateway, device, and remote-access authority that users should review before installing.
Install only if you want FridayNext to act as a high-trust mobile operator for your OpenClaw gateway. Review the gateway LAN binding, public-access standby/FridayTunnel settings, device data toggles, and the app's ability to manage agents, cron jobs, files, approvals, and plugin upgrades.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access
return execFileSync("powershell", [exec(
execSync(`${cmd} --version`, { stdio: "ignore" });const override = process.env[REGISTRY_ENV_VAR];
const sudoUser = process.env.SUDO_USER;