Loading npm security reports…
OpenClaw sandbox-backend plugin that delegates execution to a Gondolin-managed VM.
LPM treats this as warn-only first-party agent extension lifecycle risk. A startup-activated OpenClaw extension registers a Gondolin sandbox backend and authenticated local control routes. It can execute configured SSH sandbox commands at runtime, but no unconsented install-time mutation or exfiltration was found.
Package source references dynamic require/import behavior.
dist/sdk-validate.mjsView on unpkg · L23Package source references dynamic require/import behavior.
dist/sdk-validate.mjsView on unpkg · L23