Skill Trust Decision

zulip-bridge

Legitimate Zulip messaging bridge plugin with no malicious behavior, proper credential handling, and strong security controls including SSRF protection, path traversal mitigation, and local file exfiltration prevention.

Install decision first Source: Manual upload Scanned: Apr 3, 2026
Files 46
Artifacts 15
Violations 0
Findings 1

Why this conclusion was reached

1/4 dimensions flagged
Pass
Declared vs actual capability

Declared resources and inferred behavior are broadly aligned.

Block
Hidden execution and egress

1 high-risk artifacts or egress signals were extracted.

Pass
Attack chain and severe findings

There is no explicit malicious chain in the report.

Pass
Dependencies and supply chain hygiene

Dependencies are present but no obvious high-risk issue stands out.

What drove the risk score up

No shell execution detected +0

No subprocess, exec, or spawn calls found

No obfuscation or suspicious encoding +0

Clean codebase with no base64/eval patterns

Credential access is legitimate +0

ZULIP_* env vars read only for Zulip API auth, not exfiltrated

Network calls restricted to configured Zulip server +0

All HTTP requests go to the user's own Zulip instance

Proactive security hardening present +-5

SSRF protection in uploads.ts, path traversal sanitization, local file exfiltration prevention

Most important evidence

Low Sensitive Access

Filesystem read access for config loading

The skill reads configuration from ~/.openclaw/openclaw.json. This is necessary for the core messaging functionality and documented in SKILL.md.

src/zulip/accounts.ts:84
No action needed. This is legitimate access for credential retrieval.

Declared capability vs actual capability

Network Pass
Declared READ
→
Inferred READ
HTTP requests only to configured Zulip server
Environment Pass
Declared READ
→
Inferred READ
Only reads ZULIP_API_KEY, ZULIP_EMAIL, ZULIP_URL (legitimate)
Filesystem Pass
Declared NONE
→
Inferred READ
Reads ~/.openclaw/openclaw.json; temp files for uploads (both documented and necessary)
Shell Pass
Declared NONE
→
Inferred NONE
No subprocess/exec calls found
Skill Invoke Pass
Declared NONE
→
Inferred NONE
No skill invocation
Clipboard Pass
Declared NONE
→
Inferred NONE
No clipboard access
Browser Pass
Declared NONE
→
Inferred NONE
No browser access
Database Pass
Declared NONE
→
Inferred NONE
No database access

Suspicious artifacts and egress

High API Key
apiKey: "other-config-api-key"

test/accounts.test.ts:74

Medium External URL
https://chat.example.com

docs/config.md:14

Medium External URL
https://staging.example.com

docs/config.md:142

Medium External URL
https://chat.example.com.

src/config-ui-hints.ts:18

Medium External URL
https://docs.openclaw.ai/channels/zulip

src/onboarding.ts:27

Medium External URL
https://env.zulipchat.com

test/accounts.test.ts:20

Medium External URL
https://config.zulipchat.com

test/accounts.test.ts:47

Medium External URL
https://other.zulipchat.com

test/accounts.test.ts:76

Medium External URL
https://zulip.example.com

test/client.test.ts:16

Medium External URL
https://zulip.example.com/user_uploads/1/abc/test.png

test/path-traversal.test.ts:7

Medium External URL
https://zulip.example.com/user_uploads/3/hash789/full.pdf

test/smoke.test.ts:14

Medium External URL
https://zulip.example.com/user_uploads/1/abc-123/file.png

test/smoke.test.ts:20

Dependencies and supply chain

PackageVersionSourceKnown vulnNotes
openclaw >=2026.3.23 <2027 peerDependency No Peer dependency, platform-provided
zod indirect via overrides npm No Override to prevent unused dependency bloat

File composition

46 files · 6956 lines
TypeScript 34 files · 6178 linesMarkdown 7 files · 602 linesJSON 4 files · 158 linesJavaScript 1 files · 18 lines
Files of concern · 3
src/onboarding.ts TypeScript · 377 lines
https://docs.openclaw.ai/channels/zulip
docs/config.md Markdown · 154 lines
https://chat.example.com · https://staging.example.com
src/zulip/accounts.ts TypeScript · 170 lines
Filesystem read access for config loading
Other files · monitor.ts · actions.ts · client.ts · channel.ts · policy.test.ts · send.ts +3

Security positives

SSRF protection: upload downloads restricted to configured Zulip server origin (src/zulip/uploads.ts:100-101)
Path traversal sanitization: Content-Disposition filenames sanitized with path.basename() (src/zulip/uploads.ts:70)
Local file exfiltration prevention: mediaUrl rejects non-HTTP protocols with security warning logging (src/zulip/send.ts:146-150)
Realm setting allowlist: Only safe settings like 'name', 'description' can be updated (src/actions.ts:36)
String length validation: All user inputs capped at 10000 chars to prevent DoS
No external network calls outside of the configured Zulip server
No obfuscation, no base64-encoded payloads, no eval() calls
Comprehensive security test suite including path-traversal and send-security tests
Credential access limited to ZULIP_* prefixed env vars only for the default account
Minimal dependencies with no untrusted external packages