Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- dist/.setup/dynamic-tools-D16lOp67.mjs:2082
- Evidence
child = spawn(command, args, {
Security audit
Security checks for vulnerabilities and agentic risk
This Codex integration plugin has powerful but disclosed session and runtime controls, and I found no hidden or purpose-mismatched behavior.
Install only if you want OpenClaw to integrate deeply with Codex. Review settings for user-home sharing, native session discovery, supervision raw transcript access, write controls, native plugin exposure, and execution/sandbox policy before enabling them.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal
child = spawn(command, args, {const inspector = execFile(procfs ? process.execPath : "ps", procfs ? [
apiKey: "[REDACTED]",