Security audit
OpenCode Zen OpenClaw provider
Security checks for vulnerabilities and agentic risk
Overview
This plugin coherently adds OpenCode Zen model access and optional OpenCode session browsing, with the sensitive local session access disclosed and scoped to that feature.
Before installing, understand that enabling this provider can use your OpenCode API key for model access and can show/import local OpenCode session metadata and transcripts in OpenClaw. Disable the OpenCode Session Catalog setting if you only want model access and do not want local session browsing.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
