<p align="center"> <img src="https://raw.githubusercontent.com/osolmaz/mlclaw/main/assets/mlclaw.svg" alt="ML Claw" width="180"> </p>
LPM treats this as warn-only first-party agent extension lifecycle risk. Explicit `mlclaw bootstrap` deploys and controls an OpenClaw gateway using Hugging Face resources and optional Telegram integration. It can install the Hugging Face CLI and start local/container or hosted runtime services, but no install-time attack chain is present.
Package source references child process execution.
dist/hf-state-sync.jsView on unpkg · L4946A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/mlclaw.mjsView on unpkg · L9595A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/mlclaw.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/mlclaw.mjsView on unpkg · L47Source launches a detached bundled service that exposes a broad-bound HTTP listener.
dist/mlclaw.mjsView on unpkg · L47This report applies to mlclaw@0.4.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/hf-state-sync.jsView on unpkg · L4946A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/mlclaw.mjsView on unpkg · L9595A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/mlclaw.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/mlclaw.mjsView on unpkg · L47Source launches a detached bundled service that exposes a broad-bound HTTP listener.
dist/mlclaw.mjsView on unpkg · L47