ClawVC
Security checks across malware telemetry and agentic risk
Overview
ClawVC appears to do what it claims: it uses Git to locally snapshot the OpenClaw workspace and can change OpenClaw settings to enable a read-only plan mode.
This looks internally consistent for a Git-based workspace version-control plugin. Before installing, be comfortable with it creating/using a Git repo in your workspace, committing all non-ignored files after agent turns, and editing ~/.openclaw/openclaw.json for plan mode. Add sensitive files to .gitignore because local Git history can retain secrets even after deletion. Also ensure git is installed, since the code depends on it even though the registry requirements section did not list it.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
VirusTotal engine telemetry is currently stale for this artifact.
