Security audit
Openclaw Twitter
Security checks across malware telemetry and agentic risk
Overview
The package's code, required env var, and runtime instructions are consistent with a Twitter/X research/posting skill that uses an AIsa relay (api.aisa.one); nothing requested or installed is disproportionate to that stated purpose.
This skill is internally consistent for Twitter/X research and posting via an AIsa relay, but note these key points before installing: (1) you must provide AISA_API_KEY — that single key lets the relay act for reads and OAuth-posting, so only use a key you trust and rotate it if needed; (2) posting with attachments will upload local workspace files to https://api.aisa.one — do not attach sensitive files you don't want sent to an external service; (3) the package's Python scripts may open a browser only when you request --open-browser, and the skill promises not to ask for Twitter passwords; (4) if you need stronger guarantees, review the relay's privacy/security policy or run the scripts in a sandboxed environment and audit network traffic before supplying real credentials.
VirusTotal
No VirusTotal findings
Static analysis
No suspicious patterns detected.
