Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- dist/sanitize-outbound-C6UF2cvr.js:506
- Evidence
const child = spawn(this.cliPath, args, { stdio: [
Security audit
Security checks for vulnerabilities and agentic risk
This is a sensitive but coherent iMessage channel plugin that clearly centers on local Messages access and user-controlled sending.
Install only if you want OpenClaw to access your Messages database and send or manage iMessage/SMS conversations from a signed-in Mac. Review allowFrom, groupAllowFrom, dmPolicy, groupPolicy, actions, remoteHost, attachment roots, and native approval routing before enabling it, especially if exec approvals can be delivered through iMessage.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access
const child = spawn(this.cliPath, args, { stdio: [const storeAllowFrom = await readChannelAllowFromStore("imessage", process.env, accountInfo.accountId).catch(() => []);