Security audit
TypeSafe Catalog Router
Security checks for vulnerabilities and agentic risk
Overview
This plugin coherently routes user requests to relevant OpenClaw skills or MCP tools and requires user confirmation before use.
Install only if you are comfortable sharing skill/MCP catalog descriptions and short excerpts with the configured TypeSafe endpoint when you run suggestions. Review MCP entries for embedded secrets before using server-level routing or configs without explicit tool lists.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
