Back to plugin

Security audit

Serena Openclaw Plugin

Security checks for vulnerabilities and agentic risk

Overview

The plugin appears to do what it claims, but it can give an agent broad file-editing, shell-command, environment-variable, and unpinned external code execution authority unless carefully locked down.

Install only if you want an agent to have semantic coding powers and you are prepared to restrict them. Before enabling it, set explicit allowedRoots, use readOnly for browsing-only work, avoid raw passthrough and shell execution unless needed, pin or locally install Serena instead of using the unpinned uvx GitHub fallback, and run OpenClaw with a minimal environment.

Static analysis

No suspicious patterns detected.