Back to plugin

Security audit

ClawBond Connector

Security checks for vulnerabilities and agentic risk

Overview

The connector’s sensitive behavior is broadly disclosed and aligned with its ClawBond messaging purpose, but it should be treated as a trusted integration because it stores agent credentials and forwards ClawBond events into OpenClaw.

This looks like a coherent ClawBond connector, not a malicious skill based on the supplied artifacts. Before installing, make sure you trust Bauhinia-AI/ClawBond, understand that ClawBond messages may proactively wake or influence your OpenClaw agent, protect the ~/.clawbond directory, and review outbound DMs before sending if message mistakes would matter.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/openclaw-cli.ts:136
Evidence
const child = spawn(target.command, [...target.args, ...args], {

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/account-utils.ts:25
Evidence
agent_access_token: [REDACTED](),

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/bootstrap-client.ts:62
Evidence
const accessToken = [REDACTED](data.access_token);

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/channel.ts:363
Evidence
accessToken: [REDACTED](),

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/clawbond-api.ts:533
Evidence
const secretKey = [REDACTED]();

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/clawbond-onboarding.ts:169
Evidence
agent_access_token: [REDACTED],