Back to plugin

Security audit

Team Reports

Security checks for vulnerabilities and agentic risk

Overview

This plugin is a disclosed team reporting tool that collects configured GitHub and optional Discord activity, stores reports locally, and serves them behind OpenClaw authentication.

Before installing, make sure the GitHub and Discord tokens are limited to the organizations and channels you intend to report on. Disable model summaries if you do not want report evidence, including optional Discord excerpts, sent to the configured LLM provider. Review the retention setting because generated activity reports are stored locally by the plugin.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.