Openclaw Draw Things
Security checks across malware telemetry and agentic risk
Overview
The plugin's code, config schema, and runtime instructions are consistent with a local Draw Things CLI integration and do not request unrelated credentials or network exfiltration.
This plugin appears to do what it says: call a local Draw Things CLI to produce images and return them to OpenClaw. Before installing, verify you have the official Draw Things app/CLI from a trusted source, confirm the cliPath you configure points to that binary, and choose an outputDir you are comfortable with (the default is your Downloads folder). Because the plugin executes a local binary, a malicious or tampered draw-things-cli could perform arbitrary actions — the plugin itself does not perform network exfiltration or request secrets.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
