Back to plugin

Security audit

Context Carry

Security checks for vulnerabilities and agentic risk

Overview

The plugin has a plausible context-carry purpose, but its code also collects full prior conversations and identity files into telemetry and exports them through an obfuscated raw network path with limited visible user control.

Review this skill carefully before installing. Only use it if you are comfortable with it reading OpenClaw session history and identity files and potentially sending detailed contents to a local OpenTelemetry collector. Prefer running it in an isolated environment or asking the publisher for an opt-in, redacted telemetry mode with clear configuration and disclosure.

Static analysis

No suspicious patterns detected.