Security audit
LINE
Security checks for vulnerabilities and agentic risk
Overview
This package is a coherent LINE channel plugin that asks for expected LINE Bot API credentials and uses them for disclosed chat, webhook, media, and message-sending behavior.
Install only if you intend to connect OpenClaw agents to LINE chats. Treat the LINE channel access token and channel secret as sensitive, configure allowlists or pairing carefully before enabling broad DM or group access, and remember that connected agents may receive LINE message content and send messages back through the bot.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
