Security audit
OSCAR
Security checks for vulnerabilities and agentic risk
Overview
This is a disclosed OSCAR chat-channel plugin that connects configured screen names to OpenClaw agents, with access controls and no hidden install-time execution found.
Install only if you intend to expose an OpenClaw agent over an OSCAR server. Keep owners limited to people you would trust with powerful agent access, use TLS where available, avoid unauthenticated servers unless you accept that risk, and review any fallback routes or per-room tool overrides before enabling them.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
