Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- dist/bocha-client.js:72
- Evidence
readSecretString(process.env.BOCHA_API_KEY));
Security audit
Security checks for vulnerabilities and agentic risk
This package is a coherent Bocha web-search provider plugin that sends user search queries to Bocha using a configured API key, with no hidden install scripts, file access, or persistence found.
Before installing, understand that your search queries and Bocha API key will be sent to Bocha, or to a custom base URL if you configure one. Use the base URL override only with endpoints you trust, and store the API key through OpenClaw config or the BOCHA_API_KEY environment variable as documented.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.env_credential_access
readSecretString(process.env.BOCHA_API_KEY));