Back to plugin

Security audit

OpenCode Zen OpenClaw provider

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate OpenCode provider plugin with disclosed model, image, API-key, and native session-browsing features.

Install this only if you want OpenClaw to connect to OpenCode Zen and show local or paired-node OpenCode sessions. Be aware that enabling the native session catalog can expose OpenCode session titles, directories, transcripts, tool outputs, and attachments inside OpenClaw; disable the sessionCatalog setting if you only want the model provider.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.