Security audit
Invoice Parser
Security checks across malware telemetry and agentic risk
Overview
The skill's code, instructions, and required credential (a PDFAPIHub API key) are coherent with the declared purpose of parsing and OCR'ing invoices and exporting results; no disproportionate access or suspicious install behavior was found.
This plugin appears to do what it says: it uploads invoice PDFs to PDFAPIHub for parsing/OCR and returns structured data or converted files. Before installing: 1) confirm you trust PDFAPIHub to process sensitive invoices and verify their deletion/retention policy; 2) expect to provide a single API key (PDFAPIHUB_API_KEY) and avoid reusing highly-privileged credentials; 3) be aware the SKILL.md examples use two slightly different plugin names — double-check the exact install/config name your OpenClaw instance expects; 4) consider testing with non-sensitive/sample invoices first and rotate the API key if you later remove the plugin.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
