Back to plugin

Security audit

Anthropic Vertex

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent OpenClaw provider plugin that uses Google Vertex AI credentials to make Anthropic model calls, with no evidence of hidden persistence, destructive actions, or unrelated data access.

Install only if you intend OpenClaw to use your Google Cloud ADC credentials for Anthropic Vertex model access. Confirm the selected Google Cloud project and region are correct, because model usage may incur Vertex AI costs under those credentials.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/stream-runtime.js:44
Evidence
function createAnthropicVertexStreamFn(projectId, region, baseURL, deps = defaultAnthropicVertexStreamDeps, env = process.env) {