Okki Go
Security checks across malware telemetry and agentic risk
Overview
The plugin's code, manifest, and declared config are consistent with a B2B lead‑prospecting tool that calls an external Okki Go API and requires a plugin API key; nothing in the files indicates unrelated credential access or persistence beyond the plugin config.
This plugin appears to do exactly what it says: it talks to an Okki Go API and needs a plugin API key stored in OpenClaw's plugin config. Before installing, verify the Okki service and base URL (default https://go.dev.okki.ai) are ones you trust. Only store an API key dedicated to this plugin (do not reuse high‑privilege keys), and grant the plugin permission to save the key only after you confirm the verification response. Note: the package contains built JS and a plugin manifest (not just prose instructions) — if you want source-level review, request the original TypeScript source or an upstream homepage/repository to inspect. If you have privacy or compliance concerns about sending contact data to the external API, review Okki's documentation and policies before use.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
