Security audit
OpenClaw Zalo Mod
Security checks for vulnerabilities and agentic risk
Overview
This Zalo moderation plugin is mostly coherent, but it needs Review because it gives an owner-controlled agent broad Zalo write abilities and persistent agent-instruction changes, including some actions the docs imply are blocked.
Install only if you trust this publisher with owner-level Zalo automation. Before enabling, review the `zalo-api` actions available to the agent, keep the dashboard bound to localhost or protected by a strong token, verify who is configured as owner, and remember that Zalo messages, DMs, contacts, memories, and reports are persisted locally for the plugin to use.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
