Back to plugin
Pluginv0.2.14
Static analysis security
Openclaw Murf Plugin · Deterministic local checks for risky code patterns and metadata mismatches.
Scanner verdict
SuspiciousApr 22, 2026, 7:30 AM
- Summary
- Detected: suspicious.env_credential_access
- Reason codes
- suspicious.env_credential_access
- Engine
- v2.4.0
Evidence
criticaldist/index.mjs:603
Environment variable access combined with network send.
const apiKey = config.apiKey || process.env.MURF_API_KEY;
