zulip-bridge
Legitimate Zulip messaging bridge plugin with no malicious behavior, proper credential handling, and strong security controls including SSRF protection, path traversal mitigation, and local file exfiltration prevention.
Why this conclusion was reached
1/4 dimensions flaggedDeclared resources and inferred behavior are broadly aligned.
1 high-risk artifacts or egress signals were extracted.
There is no explicit malicious chain in the report.
Dependencies are present but no obvious high-risk issue stands out.
What drove the risk score up
No subprocess, exec, or spawn calls found
Clean codebase with no base64/eval patterns
ZULIP_* env vars read only for Zulip API auth, not exfiltrated
All HTTP requests go to the user's own Zulip instance
SSRF protection in uploads.ts, path traversal sanitization, local file exfiltration prevention
Most important evidence
Filesystem read access for config loading
The skill reads configuration from ~/.openclaw/openclaw.json. This is necessary for the core messaging functionality and documented in SKILL.md.
src/zulip/accounts.ts:84 Declared capability vs actual capability
HTTP requests only to configured Zulip server Only reads ZULIP_API_KEY, ZULIP_EMAIL, ZULIP_URL (legitimate) Reads ~/.openclaw/openclaw.json; temp files for uploads (both documented and necessary) No subprocess/exec calls found No skill invocation No clipboard access No browser access No database access Suspicious artifacts and egress
apiKey: "other-config-api-key" test/accounts.test.ts:74
https://chat.example.com docs/config.md:14
https://staging.example.com docs/config.md:142
https://chat.example.com. src/config-ui-hints.ts:18
https://docs.openclaw.ai/channels/zulip src/onboarding.ts:27
https://env.zulipchat.com test/accounts.test.ts:20
https://config.zulipchat.com test/accounts.test.ts:47
https://other.zulipchat.com test/accounts.test.ts:76
https://zulip.example.com test/client.test.ts:16
https://zulip.example.com/user_uploads/1/abc/test.png test/path-traversal.test.ts:7
https://zulip.example.com/user_uploads/3/hash789/full.pdf test/smoke.test.ts:14
https://zulip.example.com/user_uploads/1/abc-123/file.png test/smoke.test.ts:20
Dependencies and supply chain
| Package | Version | Source | Known vuln | Notes |
|---|---|---|---|---|
| openclaw | >=2026.3.23 <2027 | peerDependency | No | Peer dependency, platform-provided |
| zod | indirect via overrides | npm | No | Override to prevent unused dependency bloat |
File composition
src/onboarding.ts docs/config.md src/zulip/accounts.ts