File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- node_modules/@ovrsr/fpp-protocol-core/dist/steward-authorization.d.ts:13
- Evidence
readonly authorization: "[REDACTED]";
Security audit
Security checks across malware telemetry and agentic risk
This plugin is a coherent trust and handshake integration that persists local trust state and keys as disclosed, without evidence of hidden exfiltration or destructive behavior.
Install this only if you want this workspace to maintain local FPP trust identity and governance state. Review the .openclaw/workspace paths and steward/quorum configuration, because finalized mandates or admitted emergency overrides may be consumed by a separate enforcement plugin.
SkillSpector was not run because this plugin release contains no bundled skills.
62/62 vendors flagged this plugin as clean.
Detected: suspicious.exposed_secret_literal
readonly authorization: "[REDACTED]";
authorization: "[REDACTED]",
authorization: "[REDACTED]",