Back to plugin

Security audit

E-Claw OpenClaw Channel

Security checks for vulnerabilities and agentic risk

Overview

The plugin mostly matches its E-Claw channel purpose, but it has Review-worthy handling of secrets in agent context and automatic remote account changes that users should inspect before installing.

Before installing, confirm you are comfortable giving this plugin E-Claw channel credentials and allowing it to register webhooks and bind an entity. Configure a valid public webhook URL before startup, watch for bot-to-bot prompt-injection or reply loops, and avoid running the README upgrade scripts without reviewing and pinning the version.

Static analysis

No suspicious patterns detected.