Back to plugin

Security audit

TypeSafe Catalog Router

Security checks for vulnerabilities and agentic risk

Overview

This plugin coherently routes user requests to relevant OpenClaw skills or MCP tools and requires user confirmation before use.

Install only if you are comfortable sharing skill/MCP catalog descriptions and short excerpts with the configured TypeSafe endpoint when you run suggestions. Review MCP entries for embedded secrets before using server-level routing or configs without explicit tool lists.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.