Back to plugin

Security audit

Signal

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Signal channel plugin that connects OpenClaw to a user-configured Signal setup, with sensitive messaging access that is expected for that purpose.

Install only if you want OpenClaw to send, receive, and process Signal messages through your Signal account. Keep dmPolicy/groupPolicy restrictive, configure allowFrom/groupAllowFrom carefully, and enable remote approval handling only for trusted Signal identities.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/.setup/monitor-BfwQr78f.mjs:146
Evidence
const child = spawn(opts.cliPath, args, { stdio: [