Back to plugin

Security audit

FridayNext — an iOS client for OpenClaw

Security checks for vulnerabilities and agentic risk

Overview

This mobile OpenClaw plugin appears purpose-aligned, but it grants broad gateway, device, and remote-access authority that users should review before installing.

Install only if you want FridayNext to act as a high-trust mobile operator for your OpenClaw gateway. Review the gateway LAN binding, public-access standby/FridayTunnel settings, device data toggles, and the app's ability to manage agents, cron jobs, files, approvals, and plugin upgrades.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/public-access/frpc-manager.js:771
Evidence
return execFileSync("powershell", [

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
install-runtime.js:55
Evidence
exec(

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
install.js:59
Evidence
execSync(`${cmd} --version`, { stdio: "ignore" });

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/src/npm-registry.js:64
Evidence
const override = process.env[REGISTRY_ENV_VAR];

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
install.js:16
Evidence
const sudoUser = process.env.SUDO_USER;