Security audit
DingTalk
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent DingTalk channel plugin for OpenClaw, with sensitive messaging and credential behavior disclosed and gated by configuration.
Install only if you intend OpenClaw to read and send DingTalk messages. Before production use, restrict dmPolicy/groupPolicy, keep Gateway docs/proactive-send disabled unless needed, use allowlists when enabling them, store clientSecret through approved secret providers, and leave feedback learning off unless you want persistent prompt-steering rules.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
