Environment variable access combined with network send.
- Code
- suspicious.env_credential_access
- Location
- dist/src/oauth-exchange-command.js:94
- Evidence
const code = options.code?.trim() || stringValue(process.env[CLIQ_AUTH_CODE_ENV]);
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed Zoho Cliq channel plugin for OpenClaw with broad but purpose-aligned messaging, webhook, OAuth, and setup capabilities.
Install only if you intend to expose an OpenClaw agent in Zoho Cliq. Prefer the runtime-only OAuth profile unless you need setup to create or update Cliq bots and handlers, keep DM access allowlisted or pairing-based, set session.dmScope to per-channel-peer for multi-user bots, store secrets as SecretRefs/environment variables, and rotate the webhook secret when bot editor or Bots.READ access changes.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal
const code = options.code?.trim() || stringValue(process.env[CLIQ_AUTH_CODE_ENV]);
const code = options.code?.trim() || stringValue(process.env[CLIQ_AUTH_CODE_ENV]);
clientSecret: "[REDACTED]",
clientSecret: "[REDACTED]",
clientSecret: "[REDACTED]",
Authorization: "[REDACTED]",
const oauthBody = opts.oauthBody ?? { access_token: "[REDACTED]", expires_in: 3600 };{ ...BASE, clientSecret: "[REDACTED]", webhookSecret: "wh" },const CLIENT_SECRET = "[REDACTED]";
const clientSecret = "[REDACTED]";
JSON.stringify({ access_token: "[REDACTED]", scope: FULL_SCOPE_STRING }),CLIQ_CLIENT_SECRET: "[REDACTED]",
clientSecret: "[REDACTED]",
clientSecret: "[REDACTED]",
const cfg = cfgWith({ clientSecret: "[REDACTED]" });clientSecret: "[REDACTED]",
clientSecret: "[REDACTED]",
clientSecret: "[REDACTED]",