File appears to expose a hardcoded API secret or token.
- Code
- suspicious.exposed_secret_literal
- Location
- node_modules/@ovrsr/fpp-protocol-core/dist/steward-authorization.d.ts:13
- Evidence
readonly authorization: "[REDACTED]";
Security audit
Security checks across malware telemetry and agentic risk
The plugin’s behavior is mostly disclosed and purpose-aligned, but it should be reviewed because it is a startup dispatcher hook that still allows installation on known vulnerable OpenClaw versions.
Review before installing. Use only with a patched OpenClaw runtime newer than the affected advisory ranges, and expect the plugin to inspect and gate tool calls while writing local audit, receipt, mandate, and identity files. Avoid dangerous overrides such as fail-open approval timeouts or removing default hard blocks unless you intentionally accept that risk.
SkillSpector was not run because this plugin release contains no bundled skills.
60/60 vendors flagged this plugin as clean.
Detected: suspicious.exposed_secret_literal
readonly authorization: "[REDACTED]";
authorization: "[REDACTED]",
authorization: "[REDACTED]",