Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- dist/engine.js:103
- Evidence
const child = spawn(bin, args, { stdio: ["ignore", "pipe", "pipe"] });
Security audit
Security checks for vulnerabilities and agentic risk
This plugin’s sensitive screen-reading behavior is clearly tied to its stated macOS visual-inspection purpose and is disclosed in the package.
Install only if you are comfortable granting OpenClaw Accessibility and Screen Recording access, because the tool can read text, windows, and UI structure visible on your Mac. Use the documented doctor/setup flow, and disable or clear the cache if persistent local visual state is a concern.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.dangerous_exec
const child = spawn(bin, args, { stdio: ["ignore", "pipe", "pipe"] });const res = spawnSync("openclaw", args, { encoding: "utf8", timeout: 30000 });