Security audit
OpenClaw Volcengine Provider
Security checks for vulnerabilities and agentic risk
Overview
This package is a coherent Volcengine provider plugin that uses disclosed API keys and network calls for model and text-to-speech access.
Install only if you intend to route model or speech requests through Volcengine/BytePlus and are comfortable providing those API credentials. Avoid setting a custom TTS base URL unless it is an endpoint you trust.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
