Security audit
Synology Chat
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent Synology Chat integration that needs chat credentials and webhook access, with visible safeguards and no hidden unrelated behavior found.
Install only if you intend to connect OpenClaw agents to Synology Chat. Configure a strong webhook token, keep the default allowlist posture unless public access is intentional, avoid allowInsecureSsl except for local self-signed NAS setups, and treat webhookUrl as a sensitive externally reachable callback URL for attachment delivery.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
