.Tmp Clawhub Publish 2026.3.30
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The plugin's code, README and runtime instructions align with its stated purpose (adding a DashScope/Qwen web_search provider) and only request an API key relevant to that purpose.
This plugin appears to do exactly what it claims: provide a DashScope (Qwen) web_search provider for OpenClaw. Before installing: 1) Only supply a DASHSCOPE_API_KEY if you trust the plugin/source (the key is used as a Bearer token to call https://dashscope.aliyuncs.com). 2) Note the small metadata mismatch (registry shows no env vars while the plugin does accept DASHSCOPE_API_KEY) — verify configuration precedence in your environment. 3) Install in a test environment first and confirm OpenClaw/plugin sandboxing policies you rely on. 4) If you need stronger assurance, review the included TypeScript sources (they are readable and not obfuscated) or run the tests locally.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings
Risk analysis
No visible risk-analysis findings were reported for this release.
