File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- dist/openclaw/config.js:242
- Evidence
const accessToken = [REDACTED] || '';
Security audit
Security checks for vulnerabilities and agentic risk
This package is a disclosed Instagram DM channel plugin whose sensitive behavior matches its stated purpose.
Before installing, confirm you control the Instagram professional account and Meta app, store tokens only in the gateway service environment, understand that agents can send DMs and optionally public/private comment replies, keep comment handling disabled until needed, and use allowlist mode unless you intend to accept DMs from any Instagram user.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.exposed_secret_literal
const accessToken = [REDACTED] || '';