Back to plugin

Security audit

Diagnostics Prometheus

Security checks for vulnerabilities and agentic risk

Overview

This package is a Prometheus diagnostics exporter that starts with OpenClaw and exposes runtime metrics through an authenticated operator endpoint.

Install this only where operator-authenticated metrics scraping is intended. Treat the metrics endpoint as sensitive because it can reveal runtime activity, model/provider names, tool names, and operational health data, even though the artifact does not show private payload export or hidden persistence.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.