Security audit
AxonHub
Security checks for vulnerabilities and agentic risk
Overview
The AxonHub provider is purpose-aligned overall, but its Codex bridge persistently modifies Codex configuration and creates an auth helper that can retrieve the AxonHub API key, which deserves user review before installation.
Install only if you want AxonHub integrated with OpenClaw and potentially Codex. Review the Codex bridge behavior first: when AxonHub is selected for the Codex runtime, it can add managed entries to Codex config and create a local auth wrapper that retrieves your AxonHub API key through OpenClaw's credential system. Consider disabling the bridge with AXONHUB_CODEX_BRIDGE_DISABLED if you only need normal OpenClaw provider routing.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
