Security audit
Microsoft Teams Voice (CVI)
Security checks across malware telemetry and agentic risk
Overview
This Teams bridge is mostly coherent and disclosed, but it needs Review because some installation and voice-triggered actions can grant broad authority or share meeting content without a clear confirmation step.
Install through the reviewed OpenClaw package path rather than piping the remote installer to bash. Keep inboundPolicy on allowlist, leave requireRecordingStatus enabled, avoid exposing the WebSocket broadly, and only set realtime.toolPolicy to owner for trusted callers. Before enabling meetingRecap or callbacks, make sure participants understand that transcripts may be summarized, saved as DOCX, and sent to Teams.
SkillSpector
SkillSpector was not run because this plugin release contains no bundled skills.
VirusTotal
61/61 vendors flagged this plugin as clean.
Static analysis
No suspicious patterns detected.
