Back to plugin

Security audit

Z.AI OpenClaw provider

Security checks for vulnerabilities and agentic risk

Overview

This package is a coherent Z.AI model-provider plugin that uses API keys and Z.AI endpoints for its stated purpose.

Before installing, confirm you intend to add Z.AI as a model provider and are comfortable giving OpenClaw access to a Z.AI API key. Be aware the runtime may reuse a legacy Z.AI token from ~/.pi/agent/auth.json for usage lookup if no current credential is configured.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.