Security audit
Mattermost
Security checks for vulnerabilities and agentic risk
Overview
This is a coherent Mattermost channel plugin that uses bot credentials and chat permissions for expected integration behavior, with no artifact evidence of hidden or unrelated activity.
Install only if you intend to give OpenClaw a Mattermost bot token. Review the bot account's Mattermost permissions, keep DM and group policies restrictive unless broader access is intended, and be cautious with private-network opt-in, native slash commands, native skill commands, open allowlists, and raw command-text preview settings.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
