security-triage

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: Utilizes project maintenance tools including gh, git, and npm to automate the verification of security advisories, tags, and commits within the OpenClaw repository.
  • [COMMAND_EXECUTION]: Employs pbcopy to assist the user in copying the final maintainer response to the system clipboard.
  • [SAFE]: Uses $(mktemp) for the --userconfig flag in npm view commands, which is a security best practice to prevent reading or modifying the user's global .npmrc file during automated lookups.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 04:50 AM