Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- dist/index.js:50
- Evidence
const raw = String(process.env.LEVEA_API_URL || process.env.ADSCENE_API_URL || '').replace(/\/+$/, '');
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed Levea/OpenClaw video-editing integration that sends user-directed editing requests to a backend API and is proportionate to its stated purpose.
Install only if you are comfortable using Levea as an external video-editing backend. Treat uploaded media, project scenes, reference images, and prompts as data sent to that service, keep the API key private, and use plan approval or explicit confirmation before destructive edits or exports.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.env_credential_access
const raw = String(process.env.LEVEA_API_URL || process.env.ADSCENE_API_URL || '').replace(/\/+$/, '');
process.env.LEVEA_API_URL || process.env.ADSCENE_API_URL || ''