This is a coherent WLdPass business-integration skill with real privacy and credential-handling considerations, but the sensitive behavior is mostly disclosed and aligned with its purpose.
Install only if you trust WLdPass with the business data you submit through this skill. Use a dedicated or revocable WLdPass token, protect ~/.openclaw/openclaw.json, confirm before letting an agent send messages, post demands, create public/community content, or enable auto-replies, and register webhooks only to endpoints you control because they may receive future message, match, contact, watch, and digest events.