Security audit
Tencent Cloud OpenClaw provider
Security checks for vulnerabilities and agentic risk
Overview
This package is a coherent Tencent Cloud model-provider plugin that uses user-supplied Tencent API keys for the declared provider endpoints.
Install only if you intend to use Tencent Cloud TokenHub or TokenPlan models. Expect to provide Tencent API keys and have model requests sent to Tencent's declared provider endpoints; no unrelated local data access or hidden persistence was evident in the inspected artifacts.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
