Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- index.js:11
- Evidence
const BASE_URL = (process.env.SUPERAGNT_API_URL || 'https://api.superagnt.com') + '/v1/connections/instantly'
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a disclosed Superagnt/Instantly integration, though it can perform broad email, lead, campaign, and workspace actions once configured.
Install only if you want OpenClaw agents to operate your connected Instantly account through Superagnt. Confirm any send, delete, API-key, webhook, workspace-member, or owner-change action before allowing it, and use the least-privileged Superagnt/Instantly credentials available.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.env_credential_access
const BASE_URL = (process.env.SUPERAGNT_API_URL || 'https://api.superagnt.com') + '/v1/connections/instantly'