Back to plugin

Security audit

GroupMe

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent GroupMe channel plugin that transparently uses GroupMe credentials and webhooks to let an OpenClaw agent receive and send group messages.

Install only if you intend to connect OpenClaw to a GroupMe group. Treat the GroupMe access token like a password, use a callback token and groupId binding, expose only the callback path publicly, and migrate wizard-written plaintext secrets to SecretRefs for production.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.