Back to plugin

Security audit

SMS

Security checks across malware telemetry and agentic risk

Overview

This is a coherent official OpenClaw SMS plugin that uses Twilio credentials and webhooks for expected SMS sending and receiving behavior.

Install this if you want OpenClaw to send and receive SMS through your Twilio account. Keep the Twilio auth token in a secret or environment variable, prefer pairing or an explicit allowlist, avoid dmPolicy="open" unless intentional, and only disable Twilio signature validation for local testing.

VirusTotal

61/61 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.