Back to plugin

Security audit

OpenClaw Zalo Connect

Security checks for vulnerabilities and agentic risk

Overview

This plugin transparently connects an OpenClaw agent to a personal Zalo account, with broad but disclosed messaging and account-management powers.

Install only if you want an agent to operate a Zalo personal account. Prefer a dedicated or test account, set DMs to pairing or allowlist, set groups to allowlist, restrict destructive/admin actions through tool policy where available, keep the credential files private, and enable passiveCollector only for groups where local message logging is acceptable.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:17646
Evidence
var debug = typeof process === "object" && process.env && void 0 ? (...args) => console.error("SEMVER", ...args) : () => {