Security audit
WhatsApp Agent Platform
Security checks for vulnerabilities and agentic risk
Overview
This plugin appears to do what it claims: connect configured WhatsApp Agent Platform accounts to OpenClaw agents with expected token, messaging, media, and local state access.
Install this only for WhatsApp accounts you intend to automate. Store tokens in OpenClaw's protected secret flow, prefer isolated sessions unless sharing the agent's main session is deliberate, and review the target agent's tools because inbound WhatsApp users can trigger agent runs and automatic replies.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
