Security audit
StepFun
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent StepFun model-provider plugin that registers StepFun endpoints and API-key setup without hidden persistence, broad filesystem access, or unrelated behavior.
Before installing, confirm you intend to use StepFun models and are comfortable storing or providing a StepFun API key to OpenClaw for requests to the configured StepFun endpoint. No hidden high-risk behavior was evident in the inspected artifacts.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
