Environment variable access combined with network send.
- Code
- suspicious.env_credential_access
- Location
- index.ts:43
Security audit
Security checks across malware telemetry and agentic risk
The DingTalk integration mostly matches its stated messaging purpose, but its inbound webhook handling appears to accept messages without visible DingTalk signature/origin or allowlist enforcement.
Review this plugin before installing. It appears to be a normal DingTalk messaging channel, but only use it if your OpenClaw Gateway or the plugin verifies DingTalk callback authenticity and enforces user/group allowlists. Configure a least-privilege DingTalk app or robot, avoid broad permissions, and confirm the source/version mismatch is acceptable for your environment.
64/64 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal