Security audit
OpenClaw Qianfan Provider
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent Qianfan model provider plugin that discloses its API-key setup and does not show hidden or unrelated behavior.
Install only if you intend to use Baidu Qianfan models through OpenClaw, and provide the QIANFAN_API_KEY only through the app-guided secret or documented CLI option. Review Qianfan's data handling separately because model requests will go to the configured Qianfan endpoint.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
