File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- src/fixtures/text.js:16
- Evidence
apiKey: "[REDACTED]",
Security audit
Security checks across malware telemetry and agentic risk
This is a broad but clearly disclosed OpenClaw test fixture that uses local deterministic mock behavior and does not show malicious data access or persistence.
Install this only when you want a broad OpenClaw plugin API test fixture. It registers many integration points and observes some agent lifecycle events, so keep it disabled outside testing or conformance work unless you intentionally want those mock surfaces active.
SkillSpector was not run because this plugin release contains no bundled skills.
62/62 vendors flagged this plugin as clean.
Detected: suspicious.exposed_secret_literal
apiKey: "[REDACTED]",
apiKey: "[REDACTED]",