No confirmed malicious attack surface; functionality is a first-party OpenClaw/Gondolin sandbox backend and control-session plugin. Sensitive operations are runtime, configured, and authenticated rather than install-time or import-time.
Static reason
No blocking static signals were detected.
Trigger
OpenClaw loads and registers the plugin at runtime
Impact
Runs configured sandbox backend operations and optional tool portal actions within OpenClaw/Gondolin policy
Mechanism
authenticated gateway-control and sandbox lease mediation
Rationale
The package contains dual-use agent/sandbox control code, but it is aligned with the package purpose and guarded by OpenClaw registration mode, signed gateway-control handshakes, capability projection, and explicit E2E environment gates. There is no lifecycle execution, unconsented AI-agent control-surface mutation, exfiltration, persistence, or remote payload loading from package code.
Evidence
package.jsondist/index.jsdist/openclaw-plugin-registration-8_hvRoF1.jsdist/e2e.jsdist/sdk-validate.mjsdist/openclaw.plugin.json/opt/openclaw-sdk/sandbox.js.agent-vm/e2e-tool-vm-write-read-*.txt
Network endpoints4
gateway-control://control-session/__agent-vm/ready/__agent-vm/gateway-control