Security audit
CommonStack Provider
Security checks across malware telemetry and agentic risk
Overview
This appears to be a legitimate CommonStack model-provider plugin, with expected notes around API-key use, paid external model routing, and setting CommonStack as the default model.
This looks safe to install if you intentionally want to use CommonStack as an OpenClaw model provider. Before installing, make sure you trust the package source, use a revocable CommonStack API key, understand pay-per-token billing, and confirm whether you want CommonStack set as your default model provider.
VirusTotal
VirusTotal engine telemetry is currently stale for this artifact.
Static analysis
No suspicious patterns detected.
