Security audit
DeepClaw OpenClaw Plugin
Security checks across malware telemetry and agentic risk
Overview
This appears to do what it says: collect LLM usage and cost telemetry from OpenClaw and send it to a configured DeepClaw endpoint.
Before installing, confirm that you intend to send OpenClaw LLM usage metadata—model names, provider, token counts, cache/reasoning counts, session/run IDs, and calculated cost summaries—to DeepClaw or to the `apiUrl` you configure. The source does not appear to collect prompt or response text, but usage telemetry can still reveal operational patterns. Also note that although the registry says no required environment variables, the plugin will need a DeepClaw sync token in config or `DEEPCLAW_SYNC_TOKEN` to actually run.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
