Back to plugin

Security audit

AxonHub

Security checks for vulnerabilities and agentic risk

Overview

The AxonHub provider is purpose-aligned overall, but its Codex bridge persistently modifies Codex configuration and creates an auth helper that can retrieve the AxonHub API key, which deserves user review before installation.

Install only if you want AxonHub integrated with OpenClaw and potentially Codex. Review the Codex bridge behavior first: when AxonHub is selected for the Codex runtime, it can add managed entries to Codex config and create a local auth wrapper that retrieves your AxonHub API key through OpenClaw's credential system. Consider disabling the bridge with AXONHUB_CODEX_BRIDGE_DISABLED if you only need normal OpenClaw provider routing.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.