Back to plugin

Security audit

@nevermined-io/openclaw-plugin

Security checks for vulnerabilities and agentic risk

Overview

The plugin is mostly a disclosed Nevermined payments integration, but it also automatically enforces and settles payments around other gateway tool calls when plans are configured.

Review this carefully before installing on a gateway with real Nevermined plans or enrolled cards. Use sandbox first, keep spending limits low, only configure plans where automatic cross-tool payment enforcement is intended, and avoid sending payment-signature tokens to untrusted or non-HTTPS agent URLs.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/auth.js:119
Evidence
execFile(cmd, args, (err) => {