Back to plugin

Security audit

Bocha

Security checks for vulnerabilities and agentic risk

Overview

This package is a coherent Bocha web-search provider plugin that sends user search queries to Bocha using a configured API key, with no hidden install scripts, file access, or persistence found.

Before installing, understand that your search queries and Bocha API key will be sent to Bocha, or to a custom base URL if you configure one. Use the base URL override only with endpoints you trust, and store the API key through OpenClaw config or the BOCHA_API_KEY environment variable as documented.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/bocha-client.js:72
Evidence
readSecretString(process.env.BOCHA_API_KEY));