Back to plugin

Security audit

Tinker WhatsApp

Security checks for vulnerabilities and agentic risk

Overview

This WhatsApp plugin mostly matches its purpose, but it also has under-disclosed local history indexing/backfill and ambiguous install provenance that users should review first.

Install only if you are comfortable linking a real WhatsApp account to OpenClaw, letting it read and send WhatsApp messages under your configured policies, and potentially keeping searchable local copies of message history. Verify the publisher/package naming mismatch and review history retention, logging, and backend settings before use.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/channel-plugin-api.js:489
Evidence
exports.exec = function exec(sql) {