Back to plugin

Security audit

Command Code

Security checks across malware telemetry and agentic risk

Overview

This package is a disclosed OpenClaw model-provider plugin that routes selected model traffic to Command Code using a user-provided API key.

Install this only if you intend to use Command Code as a model provider. Model prompts and completions will be sent to Command Code when you select these models, and inference requires a Command Code API key; treat that key as a secret and use OpenClaw's normal credential handling.

SkillSpector

By NVIDIA

SkillSpector was not run because this plugin release contains no bundled skills.

VirusTotal

33/33 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.