Back to plugin

Security audit

Contro1 Approvals

Security checks across malware telemetry and agentic risk

Overview

This approval plugin is not malicious, but it needs Review because its security-gating behavior has version and policy gaps users should understand.

Install only on a patched OpenClaw host and treat the default policy as a heuristic, not a complete security boundary. Review or override CONTRO1_TOOL_POLICY if you need secret-read tools, credential managers, or other sensitive read operations to require approval, and run the external bridge only if you accept its separate trust model.

SkillSpector

By NVIDIA

SkillSpector was not run because this plugin release contains no bundled skills.

VirusTotal

65/65 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.