Back to plugin

Security audit

Aquaman: API Key Protection

Security checks across malware telemetry and agentic risk

Overview

The plugin's credential-proxy behavior is disclosed and mostly coherent, but its credential-handling install stack includes vulnerable or under-pinned components that merit Review before installation.

Install only if you trust the publisher and can run it on a fully updated OpenClaw host. Prefer a release that pins or updates the vulnerable dependency chain, and review the configured services because this plugin will spawn a local credential proxy, override fetch for selected API hosts, and may create placeholder OpenClaw auth profiles.

SkillSpector

By NVIDIA

SkillSpector was not run because this plugin release contains no bundled skills.

VirusTotal

61/61 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/src/proxy-manager.js:83
Evidence
const proc = spawn(binary, args, {