Back to plugin

Security audit

Signal OpenClaw channel

Security checks across malware telemetry and agentic risk

Overview

This is an official Signal integration for OpenClaw that behaves like a chat channel plugin and does not show evidence of hidden or malicious behavior.

Install only if you want OpenClaw connected to a Signal account. Review Signal allowlists, group policy, and approval routing before enabling exec/plugin approvals, because authorized Signal senders may be able to approve sensitive actions through this channel.

VirusTotal

61/61 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/monitor-Bee8O5Ay.js:85
Evidence
const child = spawn(opts.cliPath, args, { stdio: [