Security audit
OpenCode Zen OpenClaw provider
Security checks across malware telemetry and agentic risk
Overview
The artifact is a coherent OpenClaw provider plugin for OpenCode models and session browsing, with expected API-key and local session access and no evidence of hidden or destructive behavior.
Install this if you want OpenClaw to use OpenCode Zen models and browse or continue OpenCode sessions. Review the session catalog setting if local OpenCode transcripts may contain sensitive content, and only configure an OpenCode API key you are comfortable using for model and image-understanding requests.
SkillSpector
By NVIDIA
SkillSpector was not run because this plugin release contains no bundled skills.
VirusTotal
61/61 vendors flagged this plugin as clean.
Static analysis
No suspicious patterns detected.
