Security audit
PDF & Image OCR
Security checks across malware telemetry and agentic risk
Overview
The plugin is coherent with its stated purpose (cloud OCR via PDFAPIHub) but the registry metadata vs plugin manifest disagree about required credentials and you should be aware that documents are uploaded to a third‑party service.
This plugin implements cloud OCR via PDFAPIHub and requires an API key. Before installing: (1) verify the PDFAPIHub service and privacy policy (the docs claim files are uploaded and auto-deleted after 30 days), (2) do not send highly sensitive documents unless you accept third-party processing, (3) configure the API key only in plugin config or a restricted environment variable and rotate the key if needed, (4) note the small metadata inconsistency (registry summary omitted the required env var) — confirm that you must supply PDFAPIHUB_API_KEY or apiKey in openclaw.json. If you need offline/local OCR for sensitive data, consider a local Tesseract-based skill instead.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
