Back to plugin

Security audit

PDF & Image OCR

Security checks across malware telemetry and agentic risk

Overview

The plugin is coherent with its stated purpose (cloud OCR via PDFAPIHub) but the registry metadata vs plugin manifest disagree about required credentials and you should be aware that documents are uploaded to a third‑party service.

This plugin implements cloud OCR via PDFAPIHub and requires an API key. Before installing: (1) verify the PDFAPIHub service and privacy policy (the docs claim files are uploaded and auto-deleted after 30 days), (2) do not send highly sensitive documents unless you accept third-party processing, (3) configure the API key only in plugin config or a restricted environment variable and rotate the key if needed, (4) note the small metadata inconsistency (registry summary omitted the required env var) — confirm that you must supply PDFAPIHUB_API_KEY or apiKey in openclaw.json. If you need offline/local OCR for sensitive data, consider a local Tesseract-based skill instead.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal