Back to plugin

Security audit

llama.cpp Provider

Security checks for vulnerabilities and agentic risk

Overview

This plugin coherently provides llama.cpp model support and discloses its local server setup, downloads, and external-server connection behavior.

Before installing, expect this provider to use disk space for verified llama.cpp binaries and GGUF models, run a local llama-server under OpenClaw when you choose managed setup, and store an API key only if you configure an existing server that requires one.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/index.js:403
Evidence
execFile(command, args, {

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/index.js:1793
Evidence
const apiKey = [REDACTED]) ? await resolveLlamaServerRuntimeApiKey({ config: ctx.config }) : void 0;