Back to plugin

Security audit

Openclaw Stalwart Jmap Plugin

Security checks for vulnerabilities and agentic risk

Overview

The plugin's code, instructions, and manifest are consistent with a JMAP mail/calendar/contacts integration and request only the configuration credentials appropriate for that purpose.

This plugin appears to do exactly what it claims: provide JMAP tools for a Stalwart server. Before installing, ensure you trust the Stalwart server you will configure and supply only mailbox credentials or an OAuth access token (do not paste admin/API management keys). Prefer installing the published package or inspect the built dist/compiled code (dist/index.js) if you plan to install from source. If you restrict tools with tools.allow, include only this plugin id if you want to allow it. If you have low trust, run the smoke tests listed in SKILL.md in a disposable account first.

Static analysis

No suspicious patterns detected.