Back to plugin
Pluginv0.2.14

Static analysis security

Openclaw Murf Plugin · Deterministic local checks for risky code patterns and metadata mismatches.

Scanner verdict

SuspiciousApr 22, 2026, 7:30 AM
Summary
Detected: suspicious.env_credential_access
Reason codes
suspicious.env_credential_access
Engine
v2.4.0

Evidence

criticaldist/index.mjs:603
Environment variable access combined with network send.
const apiKey = config.apiKey || process.env.MURF_API_KEY;