LPM treats this as warn-only first-party agent extension lifecycle risk. First-party OpenClaw extension activates on host startup and exposes task-dispatch capabilities. It persists metrics, approvals, checkpoints, and audit logs under the host plugin root/.openclaw; no confirmed covert network or credential-exfiltration path was found.
Static reason
No blocking static signals were detected.
Trigger
OpenClaw loads the configured plugin; dispatch requires a tool, CLI, slash-command, or operator-scoped gateway request.
Impact
Authorized operators can cause configured subagents to execute engineering-task workflows; explicit dashboard commands can launch a local dashboard process.
Mechanism
Registers agent-dispatch tools and invokes the host subagent runtime.
Rationale
The package is not malicious by source inspection, but it is a startup-loaded AI-agent extension with task-execution capability and local process-launching CLI functionality. It contains no lifecycle hook or concrete exfiltration, payload, or stealth-persistence chain.
Evidence
package.jsonopenclaw.plugin.jsondist/index.jsdist/dispatch-service.jsdist/gateway.jsdist/commands/dashboard.jsdist/redis-queue-backend.js.openclaw/metrics.json.openclaw/decisions.json.openclaw/pipeline-checkpoints.json.openclaw/audit/~/.openclaw/dashboard.pid