Code Pluginsource linked

DingTalk Channelv0.8.20

Official OpenClaw DingTalk channel plugin | 钉钉官方 OpenClaw 插件

@dingtalk-real-ai/dingtalk-connector·runtime dingtalk-connector·by @dingtalk-real-ai
Community code plugin. Review compatibility and verification before install.
openclaw plugins install clawhub:@dingtalk-real-ai/dingtalk-connector
Latest release: v0.8.20Download zip

Compatibility

Built With Open Claw Version
2026.4.9
Min Gateway Version
2026.4.9
Plugin Api Range
>=2026.4.9
Plugin Sdk Version
2026.4.9
Security Scan
VirusTotalVirusTotal
stale
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The stated DingTalk channel purpose is coherent with the artifacts, but the capability set is broad: messaging, DING alerts, documents, AI tables, calendars, todos, reports, and media.
!
Instruction Scope
The channel exposes high-impact DingTalk actions while the configuration schema shows open default DM/group policies, so users should not rely on the defaults without tightening access controls.
Install Mechanism
Setup uses an npx installer that runs package code, obtains DingTalk credentials, writes OpenClaw configuration, and restarts the gateway; this is purpose-aligned but materially changes the local OpenClaw environment.
!
Credentials
Using this in an enterprise workspace could expose business data or allow account actions from chat prompts unless allowlists and group restrictions are configured.
Persistence & Privilege
The installer stores DingTalk client secrets locally and the channel keeps conversation context; the artifacts show conversation isolation defaults, but the credential files still need protection.
Scan Findings in Context
[suspicious.exposed_secret_literal] expected: The visible snippets are clientSecret schema/config/credential-handling paths rather than a shown hardcoded secret value; however, the plugin does handle and persist DingTalk secrets.
[pre-scan.system-prompt-override] expected: The supplied artifacts include configurable systemPrompt fields and safety text, but the quoted SKILL.md does not show a concrete prompt override aimed at this review.
[capability.executes-code] expected: A channel plugin installed through npx/npm is expected to execute local setup/runtime code; treat this as an install-time trust decision, not as malicious by itself.
What to consider before installing
Install only if you are comfortable letting OpenClaw act through your DingTalk authorization. Before using it in any company workspace, restrict dmPolicy/groupPolicy with allowlists, keep mention requirements on, require confirmation for destructive actions, and protect the ~/.openclaw credential files.
dist/accounts-CF4oK_HZ.mjs:218
File appears to expose a hardcoded API secret or token.
dist/connection-BZd5NXuh.mjs:62
File appears to expose a hardcoded API secret or token.
dist/runtime-f4Rv6Wna.mjs:108
File appears to expose a hardcoded API secret or token.
src/channel.ts:72
File appears to expose a hardcoded API secret or token.
src/config/accounts.ts:166
File appears to expose a hardcoded API secret or token.
src/config/schema.ts:99
File appears to expose a hardcoded API secret or token.
src/core/connection.ts:145
File appears to expose a hardcoded API secret or token.
src/device-auth.ts:162
File appears to expose a hardcoded API secret or token.
src/onboarding.ts:308
File appears to expose a hardcoded API secret or token.
Patterns worth reviewing
These patterns may indicate risky behavior. Check the VirusTotal and OpenClaw results above for context-aware analysis before installing.

Verification

Tier
source linked
Scope
artifact only
Summary
Validated package structure and linked the release to source metadata.
Commit
ef0417575bb8
Tag
ef0417575bb864aa56a5afa357535f2a68bae1e0
Provenance
No
Scan status
suspicious

Tags

latest
0.8.20
<div align="center"> <img alt="DingTalk" src="https://raw.githubusercontent.com/DingTalk-Real-AI/dingtalk-openclaw-connector/main/docs/images/dingtalk.svg" width="72" height="72" /> <h1>OpenClaw DingTalk/钉钉 插件</h1> <p>钉钉官方出品的 OpenClaw 钉钉 Channel 插件,将你的 OpenClaw Agent 无缝连接到钉钉,<br/>赋予其直接收发消息、操作文档、管理日程、协同待办等能力。</p> <p> <a href="https://www.npmjs.com/package/@dingtalk-real-ai/dingtalk-connector"><img src="https://img.shields.io/npm/v/@dingtalk-real-ai/dingtalk-connector.svg?style=flat&colorA=18181B&colorB=28CF8D" alt="npm version" /></a> <a href="https://www.npmjs.com/package/@dingtalk-real-ai/dingtalk-connector"><img src="https://img.shields.io/npm/dm/@dingtalk-real-ai/dingtalk-connector.svg?style=flat&colorA=18181B&colorB=28CF8D" alt="npm downloads" /></a> <a href="https://github.com/DingTalk-Real-AI/dingtalk-openclaw-connector/blob/main/LICENSE"><img src="https://img.shields.io/github/license/DingTalk-Real-AI/dingtalk-openclaw-connector.svg?style=flat&colorA=18181B&colorB=28CF8D" alt="license" /></a> </p> <p> <a href="README.en.md">English</a> • <a href="CHANGELOG.md">更新日志</a> • <a href="https://openclaw.ai/">OpenClaw 官网</a> </p> </div>

特性

本插件为 OpenClaw 提供全面的钉钉集成能力:

类别能力
📄 钉钉文档创建、追加、搜索、列举钉钉文档
🔔 DING 消息向用户/群发送强提醒 DING
💬 消息收发接收群聊/私聊消息,自动回复,发送文本/Markdown,@成员
✅ 待办任务创建个人待办,查状态,设截止时间
📊 AI 表格创建表格,读写行数据,条件查询
📅 日历日程日历管理、日程管理(创建/查询/修改/删除/搜索)、参会人管理、忙闲查询
📝 日志提交日报/周报,查历史日志

此外,插件还支持:

  • 🌊 AI Card 流式响应:打字机效果,在消息卡片中实时流式显示回复
  • 📱 交互式卡片:实时状态更新(思考中/生成中/完成),敏感操作确认按钮
  • 🔒 权限策略:为私聊和群聊提供灵活的访问控制策略
  • ⚙️ 多 Agent 路由:将多个机器人连接到不同 Agent,实现专业化服务
  • 🖼️ 富媒体处理:接收图片/音频/文件附件,自动上传本地图片
  • 🔄 会话管理:多轮对话上下文保持,私聊/群聊会话隔离

🚧 Coming Soon — 以下能力正在开发中,敬请期待!

类别能力
✅ 待办任务创建群待办,查状态,设截止时间
📁 文件云盘上传/下载文件到钉钉云盘

安全与风险提示(使用前必读)

本插件对接 OpenClaw AI 自动化能力,存在模型幻觉、执行不可控、提示词注入等固有风险。授权钉钉权限后,OpenClaw 将以你的用户身份在授权范围内执行操作,可能导致敏感数据泄露或越权操作等高风险后果,请谨慎使用。

为降低风险,插件已在多个层面启用默认安全保护,但风险仍然存在。我们强烈建议不要主动修改任何默认安全配置;一旦放开相关限制,风险将显著提高,后果需由你自行承担。

建议将接入 OpenClaw 的钉钉机器人作为个人对话助手使用,避免在企业生产环境中直接部署。若需在公司账号中使用,请遵守公司信息安全规范。

使用本插件即视为你已充分知悉并自愿承担所有相关风险与责任。


安装与要求

开始之前,请确保:

  • OpenClaw:已安装并正常运行。详情请访问 OpenClaw 官网
  • 版本要求:OpenClaw ≥ 2026.4.9,通过 openclaw -v 查看

如低于此版本,执行 npm install -g openclaw 升级。

一键安装 + 扫码授权(推荐)

npx -y @dingtalk-real-ai/dingtalk-connector install

安装过程中终端会显示钉钉授权二维码,使用钉钉手机 App 扫码,点击「一键创建新机器人」即可完成授权。

看到 Success! Bot configured. 即表示授权完成。之后重启 Gateway:

openclaw gateway restart

💡 扫码失败不影响安装:即使扫码流程出现问题(如超时、二维码无法显示等),插件本身仍会正常安装。你可以稍后参考 手动配置指南 完成凭证配置。


使用指南

OpenClaw 钉钉官方插件使用指南


进阶文档


贡献

欢迎社区贡献!如果你发现 Bug 或有功能建议,请提交 Issue 或 Pull Request。

对于较大的改动,建议先通过 Issue 与我们讨论。


许可证

本项目基于 MIT 许可证。


支持