Back to plugin

Security audit

Openclaw Send Agent

Security checks across malware telemetry and agentic risk

Overview

This plugin largely does what it claims, but its path handling could let an agent folder parameter escape the intended directory and email unintended local files.

Install only if you intend to let OpenClaw package local agent folders and send them from your Gmail account. Before use, verify the exact folder and recipient, install gogcli/zip from trusted sources, and prefer a fixed version that validates the resolved path stays within ~/.openclaw/agents.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.