Code Pluginsource linkedVerified

Amazon Bedrock Mantlev2026.5.28

OpenClaw Amazon Bedrock Mantle provider plugin for OpenAI-compatible model routing.

@openclaw/amazon-bedrock-mantle-provider·runtime amazon-bedrock-mantle·by @openclaw
openclaw plugins install clawhub:@openclaw/amazon-bedrock-mantle-provider
Latest release: v2026.5.28Download zip

Capabilities

configSchema
Yes
Executes code
Yes
HTTP routes
0
Providers
amazon-bedrock-mantle
Runtime ID
amazon-bedrock-mantle

Compatibility

Built With Open Claw Version
2026.5.28
Min Gateway Version
>=2026.5.12-beta.1
Plugin Api Range
>=2026.5.28
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
medium confidence
Purpose & Capability
The capability is coherent with a model-provider plugin: it registers Amazon Bedrock Mantle support and sends prompts plus provider credentials to the configured model endpoint as part of inference.
Instruction Scope
No artifact-backed evidence shows hidden agent instructions, prompt override behavior, unrelated data access, destructive actions, or user-control bypass.
Install Mechanism
The package is from the trusted @openclaw publisher context and the observed package metadata describes a normal npm/ClawHub plugin distribution without install-time script concerns.
Credentials
The plugin uses sensitive AWS/Mantle bearer credentials and transmits model context to a remote provider, but that is expected and proportionate for a remote LLM provider integration.
Persistence & Privilege
The provider may use discovery caching or token refresh behavior, but there is no evidence of broad persistence, privilege escalation, local indexing, or background mutation outside the provider purpose.
Scan Findings in Context
[SQP-2] expected: The flagged Anthropic SDK browser-access options and auth-bearing request path are sensitive, but the reviewed context supports this as provider runtime code for a model endpoint, not evidence that secrets are exposed to an arbitrary browser page or exfiltrated outside the intended provider flow.
Assessment
Install this only if you intend OpenClaw to use Amazon Bedrock Mantle models. Treat configured AWS_BEARER_TOKEN_BEDROCK or IAM credentials as sensitive, and expect prompts, attachments included in model context, and generated outputs to be sent to the configured Mantle provider endpoint during model calls.
dist/discovery.js:210
File appears to expose a hardcoded API secret or token.
Patterns worth reviewing
These patterns may indicate risky behavior. Check the VirusTotal and OpenClaw results above for context-aware analysis before installing.

Verification

Tier
source linked
Scope
artifact only
Summary
Validated package structure and linked the release to source metadata.
Commit
e93216080aa1
Tag
refs/heads/release/2026.5.28
Provenance
No
Scan status
clean

Tags

alpha
2026.5.19-alpha.1
beta
2026.6.1-beta.1
latest
2026.5.28