Security audit
OpenClaw Groq Provider
Security checks for vulnerabilities and agentic risk
Overview
This package is a coherent Groq provider plugin that sends selected model and audio requests to Groq using a user-supplied API key, with no evidence of hidden persistence, destructive behavior, or unrelated data access.
Install this only if you intend to use Groq as a model or transcription provider. Provide a Groq API key through the guided secret/env-var flow, and understand that requests handled by this provider, including audio transcription requests, may be sent to Groq's API.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
