Security audit
SeaTalk
Security checks for vulnerabilities and agentic risk
Overview
This is a disclosed SeaTalk messaging plugin whose network, credential, message, and media access fit its stated integration purpose.
Install only if you intend OpenClaw agents to interact with SeaTalk. Review SeaTalk app permissions, keep dmPolicy and groupPolicy restricted unless open access is intended, disable unneeded history tools, prefer wss:// relay URLs, and treat configured App Secret and Signing Secret as sensitive credentials.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
