Back to plugin

Security audit

Signal

Security checks for vulnerabilities and agentic risk

Overview

This package is a coherent Signal channel plugin whose sensitive behavior is disclosed and aligned with sending, receiving, and approving OpenClaw activity through Signal.

Before installing, confirm you want OpenClaw connected to this Signal account and keep allowFrom, groupAllowFrom, dmPolicy, groupPolicy, and approval routes restricted to trusted contacts. Be aware that enabling the gateway may start signal-cli locally and that Signal contacts approved through the configured policies may send messages or approve OpenClaw actions.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/monitor-CokYfKOk.js:136
Evidence
const child = spawn(opts.cliPath, args, { stdio: [