ClawAudit verdict
context-compactor
Context Compactor is a local context management plugin that estimates tokens client-side and summarizes older messages; it installs to local directories only and performs no network calls or data exfiltration.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Recursive delete from root or home โ destructive command
README.md ยท code ยท rm -rf ~
Accesses OpenClaw config/secrets directly
README.md ยท code ยท ~/.openclaw/openclaw.json
Instructs covert action โ may act without user awareness
cli.js ยท prose ยท downgraded ยท silently
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.