Security audit
ISPConfig
Security checks for vulnerabilities and agentic risk
Overview
This plugin coherently exposes ISPConfig administration tools and includes clear default safeguards, but users should configure it with least-privilege API credentials and a narrow allowlist.
Install only if you intend to let OpenClaw manage an ISPConfig server. Use a dedicated ISPConfig Remote User with the minimum API permissions needed, keep readOnly enabled by default, set allowedOperations to a small explicit list, and enable write tools only for deliberate administrative sessions.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
