Back to plugin

Security audit

Openclaw A2a Plugin

Security checks across malware telemetry and agentic risk

Overview

This plugin’s remote agent messaging and file handling are disclosed and purpose-aligned, but users should treat it as a network-facing integration with real privacy and credential risks.

Install only if you intend to let OpenClaw communicate with remote agents. Keep API-key authentication enabled unless every machine and user on the network path is trusted, avoid sending secrets or private files unless necessary, handle inbound files as untrusted, and protect generated API keys because they grant access to the inbound A2A endpoint.

VirusTotal

49/49 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.