Wyszukiwarka CPV
Security checks across malware telemetry and agentic risk
Overview
The plugin's code, bundled dataset, and runtime instructions are consistent with a local CPV lookup tool and do not request unrelated credentials, network calls, or privileged installation steps.
This plugin appears to be a straightforward local CPV lookup: it uses the bundled cpv.json and exposes a search tool and a /cpv command. Before installing: (1) confirm you trust the plugin source (local folder or repository) since it contains JavaScript/TypeScript code that will run in the OpenClaw gateway; (2) review the bundled cpv.json if you want to ensure no unexpected data is present; (3) if your organization restricts third-party code, consider running the plugin in a sandbox or reviewing the source files (they are small and readable). There are no requested credentials or network endpoints in the code.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
