AIsa Provider
Security checks across static analysis, malware telemetry, and agentic risk
Overview
This plugin's code, instructions, and required credential (AISA_API_KEY) align with its stated purpose of registering an AIsa provider for OpenClaw; nothing in the files indicates unexplained access or exfiltration.
This package appears internally consistent for adding an AIsa provider: it only needs your AISA_API_KEY and registers model metadata and onboarding hooks. Before installing, confirm you trust the AIsa endpoint (https://api.aisa.one) and that the API key's permissions are appropriate. Note the registry metadata in the submission omitted the required env var — verify the listed source/origin (author or ClawHub listing) if you need provenance assurance. Rotate or scope the API key if possible and review the small code bundle (it’s brief and readable) if you want additional confidence.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal engine telemetry is currently stale for this artifact.
