Back to plugin

Security audit

ThunderClaw

Security checks for vulnerabilities and agentic risk

Overview

This plugin’s behavior matches its stated purpose: it connects Thunderbird to OpenClaw agents through approved paired-device access for email transformations.

Install only if you intend Thunderbird to send selected email content or message segments to your configured OpenClaw agents/providers. Review pairing requests carefully, revoke devices you no longer use, and remember paired credentials can remain valid until expiry unless revoked.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.