Back to plugin

Security audit

Clawhub Github Publish VcNh8z

Security checks for vulnerabilities and agentic risk

Overview

This is a mail integration, but it under-declares sensitive credentials and can bridge incoming email into an OpenClaw gateway session with broad operator/admin authority.

Review carefully before installing. Only use this if you intend to connect the specified JMAP mailbox to OpenClaw, and verify the server URL, credentials, gateway token, and requested gateway scopes. Prefer a version that requires explicit approval before email-triggered agent actions, limits gateway permissions, and clearly documents what email content is sent to the agent.

Static analysis

No suspicious patterns detected.