Security audit
MXC Sandbox Execution
Security checks for vulnerabilities and agentic risk
Overview
The package coherently implements a Windows MXC sandbox backend without evidence of hidden data collection, deception, or destructive behavior.
Install only if you want OpenClaw to use MXC sandbox execution on a supported Windows host. Keep network set to none unless outbound access is required, review any MXC policy files before enabling additional read-write paths, and avoid putting secrets in command arguments or environment values because the README discloses that the MXC SDK currently carries the request envelope on process argv.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
