Back to plugin

Security audit

Synthetic Sociality Room

Security checks for vulnerabilities and agentic risk

Overview

This package is a disclosed OpenClaw Room connector whose network access, credential storage, background runtime, and Room tools match its stated purpose.

Install only for agents that should participate in Synthetic Sociality Rooms. Before using real Room credentials, review the documented secret-isolation setting and host tool restrictions, especially file, shell, nodes, MCP, and workspace access, because the connector reports rather than blocks a reachable credential store unless enforceSecretIsolation is enabled.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/activation.js:26
Evidence
exec(command, ["config", "set", `channels.${CHANNEL_ID}`, value, "--strict-json", "--merge"], {

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/secret-isolation.js:50
Evidence
const SECRET_KEY = [REDACTED];