Back to plugin

Security audit

CommonStack Provider

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate CommonStack model-provider plugin, with expected notes around API-key use, paid external model routing, and setting CommonStack as the default model.

This looks safe to install if you intentionally want to use CommonStack as an OpenClaw model provider. Before installing, make sure you trust the package source, use a revocable CommonStack API key, understand pay-per-token billing, and confirm whether you want CommonStack set as your default model provider.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.