Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- dist/.setup/dynamic-tools-DzlsLUuS.mjs:2010
- Evidence
child = spawn(command, args, {
Security audit
Security checks for vulnerabilities and agentic risk
This is a high-capability Codex integration plugin whose sensitive powers are disclosed, purpose-aligned, and gated by owner/admin controls.
Install this only if you want OpenClaw to run and supervise Codex. Review the Codex supervision, native session catalog, diagnostics upload, native plugin installation, and execution-permission settings, especially on shared machines or paired nodes.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal
child = spawn(command, args, {const inspector = execFile(procfs ? process.execPath : "ps", procfs ? [
apiKey: "[REDACTED]",