Security audit
OpenClaw Xiaomi Provider
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent Xiaomi provider plugin that uses disclosed Xiaomi API keys and endpoints, with no evidence of hidden local access, command execution, or persistence.
Install this if you intend to route model, image-capable model, usage, or text-to-speech requests through Xiaomi MiMo. Only configure Xiaomi API keys you want OpenClaw to use, since prompts and speech text sent to these providers will be processed by Xiaomi endpoints.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
