Security audit
Serena Openclaw Plugin
Security checks for vulnerabilities and agentic risk
Overview
The plugin appears to do what it claims, but it can give an agent broad file-editing, shell-command, environment-variable, and unpinned external code execution authority unless carefully locked down.
Install only if you want an agent to have semantic coding powers and you are prepared to restrict them. Before enabling it, set explicit allowedRoots, use readOnly for browsing-only work, avoid raw passthrough and shell execution unless needed, pin or locally install Serena instead of using the unpinned uvx GitHub fallback, and run OpenClaw with a minimal environment.
Static analysis
No suspicious patterns detected.
