Security audit
Moonshot OpenClaw provider
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent Moonshot/Kimi provider plugin that uses disclosed API keys and network calls for model, web search, and media-understanding features.
Before installing, understand that prompts, media sent for understanding, and Kimi web-search queries may be sent to Moonshot/Kimi using your configured API key, or to a custom base URL if you set one. The inspected artifacts disclose this provider behavior and do not show unrelated data access or hidden persistence.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
