Shell command execution detected (child_process).
- Code
- suspicious.dangerous_exec
- Location
- dist/index.js:195
- Evidence
const qrProcess = spawn(command.command, command.args, {
Security audit
Security checks across malware telemetry and agentic risk
The plugin is a coherent NovoLens bridge, but it needs Review because a bound remote client can trigger local OpenClaw security configuration changes without clear local confirmation.
Install only if you trust the NovoLens bridge and publisher. Keep the binding QR/code private because later scans can transfer the agent, and understand that the plugin polls the NovoLens platform, reports local monitoring/security telemetry, stores media/telemetry locally, and can change OpenClaw security configuration when a bound client triggers a security fix.
SkillSpector was not run because this plugin release contains no bundled skills.
60/60 vendors flagged this plugin as clean.
Detected: suspicious.dangerous_exec, suspicious.destructive_delete_command
const qrProcess = spawn(command.command, command.args, {spawn("cmd", ["/c", "start", "", filePath], { detached: true, stdio: "ignore" }).unref();return execFileSync(command, ["-NoProfile", "-Command", script], {return execSync(cmd, {return execSync(cmd, { encoding: 'utf-8', timeout, stdio: ['pipe', 'pipe', 'pipe'] }).trim();const qrProcess = spawn(command.command, command.args, {spawn("cmd", ["/c", "start", "", filePath], { detached: true, stdio: "ignore" }).unref();return execFileSync(command, ["-NoProfile", "-Command", script], {return execSync(cmd, {return execSync(cmd, { encoding: 'utf-8', timeout, stdio: ['pipe', 'pipe', 'pipe'] }).trim()rm -rf ~/.openclaw/extensions/novolens-plugin-openclaw