Security audit
Openclaw Stalwart Jmap Plugin
Security checks for vulnerabilities and agentic risk
Overview
The plugin's code, instructions, and manifest are consistent with a JMAP mail/calendar/contacts integration and request only the configuration credentials appropriate for that purpose.
This plugin appears to do exactly what it claims: provide JMAP tools for a Stalwart server. Before installing, ensure you trust the Stalwart server you will configure and supply only mailbox credentials or an OAuth access token (do not paste admin/API management keys). Prefer installing the published package or inspect the built dist/compiled code (dist/index.js) if you plan to install from source. If you restrict tools with tools.allow, include only this plugin id if you want to allow it. If you have low trust, run the smoke tests listed in SKILL.md in a disposable account first.
Static analysis
No suspicious patterns detected.
