Dynamic code execution detected.
Critical
- Code
- suspicious.dynamic_code_execution
- Location
- dist/index.js:114226
- Evidence
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);
Security audit
Security checks across malware telemetry and agentic risk
This package coherently adds an Oracle OCI model provider and its sensitive access is disclosed and limited to Oracle provider authentication and model/chat calls.
Install only if you intend OpenClaw to use your Oracle OCI tenancy. The plugin will need access to your OCI config file and the private key or token referenced by that config so it can sign Oracle API requests, and prompts/model requests will be sent to Oracle OCI under your account.
60/60 vendors flagged this plugin as clean.
Detected: suspicious.dynamic_code_execution, suspicious.env_credential_access, suspicious.exposed_secret_literal
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);return this._client.post("/v1/files", multipartFormRequestOptions({const gacPath = process.env.GOOGLE_APPLICATION_CREDENTIALS;
* { authorization: '[REDACTED]' }