Back to plugin

Security audit

CTRLRun

Security checks for vulnerabilities and agentic risk

Overview

This plugin is a disclosed safety bridge that gates OpenClaw tool calls through a local CTRLRun policy service.

Install this only if you intend to route OpenClaw tool-call metadata and parameters through CTRLRun. Review the configured bridge URL and token handling, because a non-loopback or untrusted bridge would be able to see sensitive tool arguments and influence whether tool calls run.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
openclaw.plugin.json:21
Evidence
"default": "http://127.0.0.1:8931"