Security audit
Command Code
Security checks across malware telemetry and agentic risk
Overview
This package is a disclosed OpenClaw model-provider plugin that routes selected model traffic to Command Code using a user-provided API key.
Install this only if you intend to use Command Code as a model provider. Model prompts and completions will be sent to Command Code when you select these models, and inference requires a Command Code API key; treat that key as a secret and use OpenClaw's normal credential handling.
SkillSpector
By NVIDIA
SkillSpector was not run because this plugin release contains no bundled skills.
VirusTotal
33/33 vendors flagged this plugin as clean.
Static analysis
No suspicious patterns detected.
