Security audit
StepFun OpenClaw Plugin
Security checks for vulnerabilities and agentic risk
Overview
This repository is internally consistent with its stated purpose as an OpenClaw StepFun provider plugin; it only asks for a single provider API key (STEPFUN_API_KEY) and contains no surprising installation or persistence behavior.
This appears to be a straightforward OpenClaw provider plugin prototype. Before installing or supplying credentials: (1) verify you trust the package source (the repository URL is included in package.json); (2) prefer to test in isolation using the SKILL.md recommended OPENCLAW_STATE_DIR and OPENCLAW_CONFIG_PATH to avoid touching your real OpenClaw config; (3) only provide the STEPFUN_API_KEY if you intend to use the StepFun provider; and (4) consider asking the author to correct the metadata inconsistency (registry summary vs openclaw.plugin.json) so required env vars are clear.
Static analysis
No suspicious patterns detected.
