Back to plugin

Security audit

OpenClaw Xiaomi Provider

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Xiaomi provider plugin that uses disclosed Xiaomi API keys and endpoints, with no evidence of hidden local access, command execution, or persistence.

Install this if you intend to route model, image-capable model, usage, or text-to-speech requests through Xiaomi MiMo. Only configure Xiaomi API keys you want OpenClaw to use, since prompts and speech text sent to these providers will be processed by Xiaomi endpoints.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.