Telnyx SMS/MMS Channel
Security checks across malware telemetry and agentic risk
Overview
The plugin's code, install instructions, and declared config mostly match its stated purpose (Telnyx SMS/MMS channel); nothing in the package suggests hidden or unrelated behavior, but review and care with your Telnyx API key and webhook overwrite options is advised.
This package appears to do what it says: it needs your Telnyx API key (placed in OpenClaw config or environment) so treat that key as sensitive. Before installing, consider: 1) Use a dedicated Telnyx number and Messaging Profile if you don't want this plugin to interact with an existing integration; the default is conservative but you can enable overwriteExistingWebhook or autoCreateProfile which will change Telnyx state. 2) Confirm your publicUrl and any tunnel provider (ngrok/cloudflared) are intentionally configured — the plugin will probe that URL and may attempt to use tunnels if configured. 3) Store the API key in OpenClaw secrets (not source control). 4) Note the small metadata inconsistency: registry metadata says no required env vars while the plugin manifest and README expect a Telnyx API key; ensure you provide the key in config or environment as the documentation indicates. If you need higher assurance, review the rest of dist/*.js source or run the plugin in a staging instance with a non-production Telnyx account first.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
