Back to plugin

Security audit

OpenClaw Kitchen Sink

Security checks across malware telemetry and agentic risk

Overview

This is a broad but clearly disclosed OpenClaw test fixture that uses local deterministic mock behavior and does not show malicious data access or persistence.

Install this only when you want a broad OpenClaw plugin API test fixture. It registers many integration points and observes some agent lifecycle events, so keep it disabled outside testing or conformance work unless you intentionally want those mock surfaces active.

SkillSpector

By NVIDIA

SkillSpector was not run because this plugin release contains no bundled skills.

VirusTotal

62/62 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/fixtures/text.js:16
Evidence
apiKey: "[REDACTED]",

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/runtime/providers.js:288
Evidence
apiKey: "[REDACTED]",