Back to plugin

Security audit

GitHub Copilot agent runtime

Security checks for vulnerabilities and agentic risk

Overview

This is an opt-in GitHub Copilot runtime plugin whose credential, network, tool, and session behavior matches its stated purpose.

Install this only if you intend OpenClaw to run an opt-in GitHub Copilot agent runtime. It may use your GitHub/Copilot authentication, forward BYOK model requests through a local guarded proxy, expose host-approved tools to the Copilot SDK, and persist resumable Copilot session bindings for continuity.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.