Is mig6671/stepfun-openrouter safe?
Yes. mig6671/stepfun-openrouter is safe to install. Oathe's behavioral security audit gave the stepfun-openrouter skill by mig6671 a trust score of 91/100 with 3 findings, none critical or high.
https://github.com/openclaw/skills/tree/main/skills/mig6671/stepfun-openrouter
Is mig6671/stepfun-openrouter safe to install?
This skill provides legitimate CLI integration with StepFun AI models via the OpenRouter API. The shell script performs expected API operations and contains no malicious functionality, though it does require API key access for operation.
What security issues were found in mig6671/stepfun-openrouter?
Category Scores
Findings (3)
MEDIUM Executable shell script with network requests -20 ▶
The skill contains a bash script that makes HTTP requests to external APIs. While the functionality appears legitimate (OpenRouter API integration), executable scripts pose inherent security considerations.
LOW Environment variable access -10 ▶
The shell script reads the OPENROUTER_API_KEY environment variable, which is expected functionality for API authentication but represents credential access.
INFO Standard git clone operations -10 ▶
Monitoring detected normal git clone behavior including GitHub connections and standard filesystem access patterns during installation.
Should I install mig6671/stepfun-openrouter?
Oathe's verdict for mig6671/stepfun-openrouter is SAFE with a trust score of 91/100. Recommendation: Install.