Back to plugin

Security audit

OVP Visual Preprocessor (macOS)

Security checks for vulnerabilities and agentic risk

Overview

This plugin’s sensitive screen-reading behavior is clearly tied to its stated macOS visual-inspection purpose and is disclosed in the package.

Install only if you are comfortable granting OpenClaw Accessibility and Screen Recording access, because the tool can read text, windows, and UI structure visible on your Mac. Use the documented doctor/setup flow, and disable or clear the cache if persistent local visual state is a concern.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/engine.js:103
Evidence
const child = spawn(bin, args, { stdio: ["ignore", "pipe", "pipe"] });

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/setup.js:50
Evidence
const res = spawnSync("openclaw", args, { encoding: "utf8", timeout: 30000 });