Security audit
GitHub Copilot agent runtime
Security checks for vulnerabilities and agentic risk
Overview
This is an opt-in GitHub Copilot runtime plugin whose credential, network, tool, and session behavior matches its stated purpose.
Install this only if you intend OpenClaw to run an opt-in GitHub Copilot agent runtime. It may use your GitHub/Copilot authentication, forward BYOK model requests through a local guarded proxy, expose host-approved tools to the Copilot SDK, and persist resumable Copilot session bindings for continuity.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
