File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- dist/.setup/firecrawl-fetch-provider-CcYAp_u6.mjs:38
- Evidence
const apiKey = [REDACTED])?.webSearch?.apiKey;
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent Firecrawl web search and page-scraping plugin that discloses its network use and optional API key handling.
Install this if you want OpenClaw to use Firecrawl for web search and page scraping. Configure the API key only if you trust Firecrawl with the searches and URLs you send, and be aware that scrape requests may use Firecrawl caching unless disabled by tool/config options.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.exposed_secret_literal
const apiKey = [REDACTED])?.webSearch?.apiKey;