Back to plugin

Security audit

OSCAR

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed OSCAR chat-channel plugin that connects configured screen names to OpenClaw agents, with access controls and no hidden install-time execution found.

Install only if you intend to expose an OpenClaw agent over an OSCAR server. Keep owners limited to people you would trust with powerful agent access, use TLS where available, avoid unauthenticated servers unless you accept that risk, and review any fallback routes or per-room tool overrides before enabling them.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.