Back to plugin

Security audit

Web Search Plus

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed multi-provider web search and extraction plugin; its main risks are expected third-party query/URL sharing and local API-key config handling, not hidden malicious behavior.

Install only if you are comfortable with search queries, domain filters, and extraction URLs being sent to the providers you configure. For confidential work, avoid broad auto/research routing or restrict providers, keep Keenable public mode and private URL extraction disabled unless explicitly needed, and handle setup-generated API-key JSON files as secrets.

SkillSpector

By NVIDIA

SkillSpector was not run because this plugin release contains no bundled skills.

VirusTotal

62/62 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
openclaw.plugin.json:109
Evidence
"description": "Loopback-only Hound Streamable HTTP MCP endpoint, exactly http://127.0.0.1:<port>/mcp or http://[::1]:<port>/mcp."