Security audit
Buddy Companion
Security checks for vulnerabilities and agentic risk
Overview
The plugin's code and declared metadata are consistent with a local 'cute companion' extension: it reads/writes files under your home config, generates a deterministic buddy, and injects reactions into agent prompts; it does not request external credentials or make network calls.
This skill appears internally consistent: it implements a local buddy that stores state under ~/.openclaw/extensions/buddy-companion, may read ~/.openclaw/identity/device.json, and can inject reactions into the agent's replies. It does not request API keys or make network calls. Before installing, consider: 1) review or vet the code if you want full assurance (it's included here); 2) note it will create/modify files in your home directory (soul.json and mute.json) — you can remove that directory to uninstall; 3) it uses hostname/username to seed a deterministic ID if no device file or BUDDY_USER_ID is present (purely local derivation); and 4) if you prefer no automatic reactions, disable the extension in its config or set reactProbability to 0. If you need higher assurance, run the plugin in a restricted environment or inspect/modify the source before enabling.
Static analysis
No suspicious patterns detected.
