Back to plugin

Security audit

TaskTrace MCP Plugin

Security checks for vulnerabilities and agentic risk

Overview

The plugin appears to do what it says—connect OpenClaw to TaskTrace—but it can expose very sensitive local activity data such as keystrokes, OCR, transcripts, and screenshots to the agent.

Use this plugin only if you are comfortable giving OpenClaw agent workflows access to TaskTrace’s local activity history. Review what TaskTrace records, avoid broad detailed-resource reads unless needed, and run OpenClaw without unrelated secrets in environment variables.

Static analysis

No suspicious patterns detected.