File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- dist/adapter.runtime-DDuc7sKJ.cjs:241
- Evidence
authorization: "[REDACTED]",
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent Microsoft Teams channel plugin for OpenClaw, with sensitive Teams credentials and state use that matches its stated bot-conversation purpose.
Install only if you intend OpenClaw agents to operate through Microsoft Teams. Configure the bot with least-privilege Microsoft permissions, keep DM and group allowlists restrictive, enable SSO or delegated auth only when needed, and understand that configured agents may send, edit, delete, read, and manage Teams content within allowed scopes.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.exposed_secret_literal
authorization: "[REDACTED]",