Security audit
Twilio WhatsApp Channel
Security checks for vulnerabilities and agentic risk
Overview
This plugin appears to do what it claims: connect OpenClaw to WhatsApp through Twilio, with expected credential, webhook, and media-handling requirements.
Install only if you want an official Twilio WhatsApp Business channel and accept Twilio message costs. Keep dmPolicy on allowlist unless the sender is intentionally public, store auth tokens via OpenClaw SecretRefs rather than plaintext, and review media retention because inbound and staged outbound files are written to the OpenClaw state directory.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
