Back to plugin

Security audit

DeepClaw

Security checks for vulnerabilities and agentic risk

Overview

This plugin does what it claims: it sends disclosed LLM usage and cost telemetry to a configured DeepClaw endpoint after the user enables it with a sync token.

Install only if you intend to send OpenClaw LLM usage telemetry to DeepClaw. Configure the sync token carefully, verify the apiUrl points to the DeepClaw instance you trust, and leave debug logging off unless you are comfortable with usage metadata appearing in logs.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.