File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- dist/.setup/firecrawl-fetch-provider-Cq_h8okw.mjs:38
- Evidence
const apiKey = [REDACTED])?.webSearch?.apiKey;
Security audit
Security checks for vulnerabilities and agentic risk
This plugin coherently adds Firecrawl-powered web search and page scraping, with expected external network use and credential handling.
Install only if you want OpenClaw to use Firecrawl for web search and page scraping. Expect requested queries, target URLs, and scraped page content to be sent to Firecrawl or your configured Firecrawl-compatible endpoint, and use the storeInCache setting carefully for sensitive pages.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.exposed_secret_literal
const apiKey = [REDACTED])?.webSearch?.apiKey;