Back to plugin

Security audit

McPherson Governance Connector

Security checks for vulnerabilities and agentic risk

Overview

This is a shadow-only OpenClaw governance connector that records bounded tool metadata and local receipts without taking control of tool execution.

Install this only if you want an Observa dashboard to receive shadow governance metadata about configured OpenClaw tool activity. Verify the HTTPS apiUrl and understand that credentials and receipts are stored locally in the OpenClaw profile, while remote decisions are observational and not enforcement authority.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
pairing/openclaw-profile-pairing.mjs:70
Evidence
const result = spawnSync(openclawBin, [