File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- dist/firecrawl-fetch-provider-shared-BQUWpKAv.js:35
- Evidence
const apiKey = [REDACTED])?.webSearch?.apiKey;
Security audit
Security checks across malware telemetry and agentic risk
This official OpenClaw package uses powerful capabilities for expected ClawHub and design-system workflows, with no evidence of hidden or malicious behavior.
Install this only in environments where OpenClaw/ClawHub operational access is appropriate. Review which service tokens and GitHub permissions are available to the agent before using moderation, release, email, observability, or package-publishing workflows.
62/62 vendors flagged this plugin as clean.
Detected: suspicious.exposed_secret_literal
const apiKey = [REDACTED])?.webSearch?.apiKey;
const apiKey = [REDACTED])?.webFetch?.apiKey;