Back to plugin

Security audit

McPherson Governance Connector

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed OpenClaw governance connector that records and sends bounded shadow-mode metadata only when paired and enabled, with no evidence of hidden execution, enforcement, or content exfiltration.

Before installing, confirm you trust the configured Observa/Hosted endpoint and are comfortable sharing bounded tool identity, outcome, runtime inventory, heartbeat, executable name, and argument-digest metadata when the connector is paired and enabled. Use the provided disable, kill switch, lock, and unpair controls if you need outbound observation stopped.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
pairing/openclaw-profile-pairing.mjs:70
Evidence
const result = spawnSync(openclawBin, [