Security audit
Claude Code Session Sync & Ride
Security checks for vulnerabilities and agentic risk
Overview
The plugin matches its stated session-riding purpose, but it exposes detailed local session metadata and includes optional persistent remote-control deployment without enough access-control guidance.
Install only where trusted operators are allowed to view and drive OpenClaw/Claude Code sessions. Restrict operator.read and operator.write access, review whether exposing cwd and raw session identifiers is acceptable, and do not enable the remote-control systemd service until its authentication, network exposure, account scope, and disable procedure are clear.
Static analysis
No suspicious patterns detected.
