Security audit
Browser Automation
Security checks across malware telemetry and agentic risk
Overview
This browser automation plugin is mostly transparent, but it enables high-impact browser/session access and writes executable skill files into workspaces by default, so users should review it before installing.
Install only if you want agents to control a real browser session. Review the defaults before enabling it: consider setting syncWorkspaceSkill=false if you do not want workspace skill files written automatically, manageBrowserConfig=false if you want to manage CDP and SSRF settings yourself, and avoid OPENCLAW_CHROME_SEED_PROFILE=1 unless you accept copying cookies/logins/history into the automation profile. Keep evaluate and upload disabled unless specifically needed.
SkillSpector
SkillSpector was not run because this plugin release contains no bundled skills.
VirusTotal
62/62 vendors flagged this plugin as clean.
Static analysis
No suspicious patterns detected.
