Security audit
GroupMe
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent GroupMe channel plugin that transparently uses GroupMe credentials and webhooks to let an OpenClaw agent receive and send group messages.
Install only if you intend to connect OpenClaw to a GroupMe group. Treat the GroupMe access token like a password, use a callback token and groupId binding, expose only the callback path publicly, and migrate wizard-written plaintext secrets to SecretRefs for production.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
