Openclaw Channel Imap
Security checks across malware telemetry and agentic risk
Overview
This appears to be what it claims: an IMAP/SMTP email channel plugin, though it runs real code and will use whatever mailbox credentials you configure.
Before installing, understand that this plugin gives OpenClaw access to read a configured mailbox and send replies through the configured SMTP account. That matches its purpose, but it is powerful: use a dedicated mailbox, prefer a restricted secret reference such as `pass` entries for only the mail passwords, keep the allowlist/rate-limit/authentication checks enabled where possible, and avoid giving the mail-facing agent broad tools or sensitive memory. Also verify the npm package metadata/scripts if you install it manually, because the registry entry has no explicit install spec even though the package contains executable code.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
VirusTotal engine telemetry is currently stale for this artifact.
