Back to plugin

Security audit

StepFun OpenClaw Plugin

Security checks for vulnerabilities and agentic risk

Overview

This repository is internally consistent with its stated purpose as an OpenClaw StepFun provider plugin; it only asks for a single provider API key (STEPFUN_API_KEY) and contains no surprising installation or persistence behavior.

This appears to be a straightforward OpenClaw provider plugin prototype. Before installing or supplying credentials: (1) verify you trust the package source (the repository URL is included in package.json); (2) prefer to test in isolation using the SKILL.md recommended OPENCLAW_STATE_DIR and OPENCLAW_CONFIG_PATH to avoid touching your real OpenClaw config; (3) only provide the STEPFUN_API_KEY if you intend to use the StepFun provider; and (4) consider asking the author to correct the metadata inconsistency (registry summary vs openclaw.plugin.json) so required env vars are clear.

Static analysis

No suspicious patterns detected.