Openclaw Nextcloud Talk 2026.5.26.Tgz

Security checks across malware telemetry and agentic risk

Overview

This official OpenClaw Nextcloud Talk channel plugin behaves like a webhook-based chat integration, with one network-exposure hardening note but no evidence of malicious behavior.

Install only if you intend to connect OpenClaw to a Nextcloud Talk instance. Configure webhookHost to 127.0.0.1 when using a local reverse proxy, expose the webhook only through trusted TLS/proxy rules, keep the bot secret and API password in a secret store or environment variable, and use room/user allowlists for who may trigger the agent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The webhook monitor defaults to binding the HTTP server to 0.0.0.0, which exposes the listener on all network interfaces unless the operator explicitly overrides webhookHost. Although the endpoint uses HMAC verification and backend-origin checks, broad exposure still increases attack surface for brute-force attempts, malformed-request abuse, and accidental internet exposure in self-hosted deployments.

VirusTotal

59/59 vendors flagged this plugin as clean.

View on VirusTotal