Security audit
Connect Microsoft 365 to OpenClaw
Security checks for vulnerabilities and agentic risk
Overview
This Microsoft 365 plugin requests sensitive mail, calendar, OneDrive, and To Do access, but the artifacts clearly disclose the access model, default-deny policy, approvals, credential vault, and operator controls.
Install only if you are comfortable granting a delegated Microsoft account credential to OpenClaw. Start with read-only policy grants, keep warning approvals enabled unless intentionally disabled, protect the vault key and backups, and remember the shared credential can carry the union of all consented Microsoft scopes.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
