Back to plugin

Security audit

Receipts

Security checks for vulnerabilities and agentic risk

Overview

This package is a coherent local receipt/audit-log tool that stores task evidence on disk, with no artifact-backed sign of exfiltration or deception.

Install only if you are comfortable with local .receipts/ files containing task prompts, agent outputs, command logs, git diffs, workspace paths, and OpenClaw session metadata. Exclude .receipts/ from commits/backups when it may contain sensitive work, and use captureMode, dryRun, workspaceDir, and skipSessionKeyPrefixes to limit what is recorded.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/cli.js:253
Evidence
const result = spawnSync(commandArgs[0], commandArgs.slice(1), {