Security audit
Hi Openclaw Plugin
Security checks for vulnerabilities and agentic risk
Overview
This Hirey Hi integration is broad and persistent, but its local changes, identity binding, event delivery, and platform access are disclosed and aligned with its setup purpose.
Install only if you want Hirey Hi to run inside your OpenClaw gateway, keep a local Hi credential, enable plugin tools, and route Hi events into your chats. Do not bind Google, phone, or email unless you are comfortable sharing that identifier with the Hi platform for identity verification.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
