Back to plugin

Security audit

Codex

Security checks for vulnerabilities and agentic risk

Overview

This is a high-capability Codex integration plugin whose sensitive powers are disclosed, purpose-aligned, and gated by owner/admin controls.

Install this only if you want OpenClaw to run and supervise Codex. Review the Codex supervision, native session catalog, diagnostics upload, native plugin installation, and execution-permission settings, especially on shared machines or paired nodes.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/.setup/dynamic-tools-DzlsLUuS.mjs:2010
Evidence
child = spawn(command, args, {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/.setup/transport-stdio-Bdegpn2V.mjs:139
Evidence
const inspector = execFile(procfs ? process.execPath : "ps", procfs ? [

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/.setup/native-auth-CuG53tu4.mjs:43
Evidence
apiKey: "[REDACTED]",