Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- dist/api.js:56
- Evidence
const base = trimmed(settings.apiBase) ?? trimmed(process.env.DNSDOCTOR_API_BASE) ?? DEFAULT_API_BASE;
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed DNS Doctor OpenClaw plugin that sends DNS-related requests to the DNS Doctor API and does not show hidden or destructive behavior.
Install only if you are comfortable sending the domains you check, DNS data, and any uploaded DMARC report files to DNS Doctor. Configure a DNS Doctor API token only for accounts whose monitoring data you want the agent to read, and keep human approval in the loop before publishing any generated DNS records.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.env_credential_access
const base = trimmed(settings.apiBase) ?? trimmed(process.env.DNSDOCTOR_API_BASE) ?? DEFAULT_API_BASE;