File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- dist/openclaw/config.js:242
- Evidence
const accessToken = [REDACTED] || '';
Security audit
Security checks across malware telemetry and agentic risk
This plugin coherently connects configured Instagram professional-account DMs to OpenClaw and does not show hidden or purpose-mismatched behavior.
Install only if you intend to let an OpenClaw agent read and answer messages for the configured Instagram professional account. Keep comment handling disabled unless you want automated private/public comment responses, use allowlists when broad DM access is not desired, and store Meta secrets only in the gateway service environment.
SkillSpector was not run because this plugin release contains no bundled skills.
60/60 vendors flagged this plugin as clean.
Detected: suspicious.exposed_secret_literal
const accessToken = [REDACTED] || '';