The plugin has a coherent intent-sharing purpose, but its triggered-notification path can run a shell command built from user- or agent-controlled text, so it needs review before installation.
Review or patch the plugin before installing. The main required fix is to replace execSync string execution with execFile or spawn using argument arrays, validate notify_agent against configured agent IDs, and limit or sanitize trigger messages. Also configure narrow agent scopes, avoid storing secrets or full financial/email payloads in trigger_data or activity logs, and use restrictive permissions and short retention for ~/.openclaw/intents.