Back to plugin

Security audit

DeepClaw OpenClaw Plugin

Security checks across malware telemetry and agentic risk

Overview

This appears to do what it says: collect LLM usage and cost telemetry from OpenClaw and send it to a configured DeepClaw endpoint.

Before installing, confirm that you intend to send OpenClaw LLM usage metadata—model names, provider, token counts, cache/reasoning counts, session/run IDs, and calculated cost summaries—to DeepClaw or to the `apiUrl` you configure. The source does not appear to collect prompt or response text, but usage telemetry can still reveal operational patterns. Also note that although the registry says no required environment variables, the plugin will need a DeepClaw sync token in config or `DEEPCLAW_SYNC_TOKEN` to actually run.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal