Security audit
TaskTrace MCP Plugin
Security checks for vulnerabilities and agentic risk
Overview
The plugin appears to do what it says—connect OpenClaw to TaskTrace—but it can expose very sensitive local activity data such as keystrokes, OCR, transcripts, and screenshots to the agent.
Use this plugin only if you are comfortable giving OpenClaw agent workflows access to TaskTrace’s local activity history. Review what TaskTrace records, avoid broad detailed-resource reads unless needed, and run OpenClaw without unrelated secrets in environment variables.
Static analysis
No suspicious patterns detected.
