Security audit
Mattermost
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent Mattermost channel plugin that uses a bot token to connect OpenClaw to Mattermost, with the expected chat, slash command, interaction, and access-control behavior disclosed in its artifacts.
Install only with a bot token whose Mattermost permissions match the channels and actions you want OpenClaw to have. Review allowFrom, groupPolicy, dmPolicy, native slash command settings, interactions.allowedSourceIps, and the private-network opt-in before enabling it on a shared or sensitive Mattermost server.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
