Security audit
Microsoft Teams
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent Microsoft Teams channel plugin whose Teams credentials, messaging, Graph access, and stored channel state are disclosed and purpose-aligned.
Install only if you intend OpenClaw agents to operate in Microsoft Teams. Configure Teams app credentials carefully, keep dmPolicy/groupPolicy and allowlists restrictive, and enable delegated Graph/OAuth features or group management actions only for workspaces where the bot should read or modify Teams content.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
