Back to plugin

Security audit

WeChat (iLink)

Security checks for vulnerabilities and agentic risk

Overview

This WeChat connector mostly matches its purpose, but it has review-worthy behavior that can send local media files named in a WeChat message and can change account configuration from chat commands.

Install only if you are comfortable exposing your OpenClaw agent through WeChat and storing WeChat bot tokens in local OpenClaw config. Before enabling it, restrict who can message the channel, review whether /wechat-login is limited to trusted users, and treat the local media path auto-send behavior as a bug or policy risk that should be fixed before broad use.

Static analysis

No suspicious patterns detected.