Security audit
GitHub Copilot agent runtime
Security checks for vulnerabilities and agentic risk
Overview
This package appears to be a coherent GitHub Copilot runtime integration, with sensitive access that is expected for that purpose.
Install only if you intend to route selected OpenClaw agent runs through GitHub Copilot or configured BYOK providers. Review which auth source will be used and which host tools the selected runtime can access, because allowed coding tools can read or change workspace files and run commands under OpenClaw's normal controls.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
