Code Pluginsource linkedVerified

Discordv2026.7.1

OpenClaw Discord channel plugin for channels, DMs, commands, and app events.

@openclaw/discord·runtime discord·by @openclaw
openclaw plugins install clawhub:@openclaw/discord
Latest release: v2026.7.1Download zip

Compatibility

Built With Open Claw Version
2026.7.1
Min Gateway Version
>=2026.5.26
Plugin Api Range
>=2026.7.1
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
The package purpose is Discord channel, DM, command, event, voice, and message tooling; send/read/edit/delete/search/pin/thread/presence and optional admin/moderation capabilities are expected for that purpose.
Instruction Scope
The skill instructions are concise and tell agents to respect channels.discord.actions.* gates and use explicit guild/channel/message/user IDs, but they do not spell out confirmation or privacy practices for destructive or broad read/search operations.
Install Mechanism
The artifact is an official trusted @openclaw package, installed as an npm pack with no package install scripts observed; activation on startup is false in the plugin manifest.
Credentials
Discord bot token use, Discord API/WebSocket access, optional voice dependencies, and media handling are proportionate to a Discord channel plugin and are disclosed in package metadata and configuration schema.
Persistence & Privilege
Runtime features can maintain Discord gateway sessions, thread bindings, temporary voice files, and optional spawned thread sessions, but these are purpose-aligned, configurable, and not hidden persistence.
Scan Findings in Context
[SQP-2] expected: The documented edit/delete/pin/thread actions are real state-changing Discord operations, but the artifact also exposes action gates and explicit ID targeting; this supports user caution rather than a Review verdict.
[SQP-2] expected: Read and search over Discord content are expected for this plugin, and runtime code includes guild/channel allowlist checks; the short skill text could better emphasize data minimization, but the behavior is disclosed and purpose-aligned.
Assessment
Install only for Discord servers and channels you intend OpenClaw to access. Keep the bot token secret, use guild/channel allowlists and actions gates, disable moderation/presence/thread-spawn/voice features you do not need, and confirm destructive actions such as delete, edit, pin, role, channel, kick, or ban operations before asking an agent to run them.
dist/manager.runtime-DaB-CTrt.js:97
Shell command execution detected (child_process).
dist/provider-BkfbC9FQ.js:6092
Environment variable access combined with network send.
Patterns worth reviewing
These patterns may indicate risky behavior. Check the VirusTotal and OpenClaw results above for context-aware analysis before installing.

Verification

Tier
source linked
Scope
artifact only
Summary
Validated package structure and linked the release to source metadata.
Commit
2d2ddc43d0dc
Tag
refs/tags/v2026.7.1
Provenance
No
Scan status
clean

Tags

alpha
2026.5.19-alpha.1
beta
2026.7.2-beta.3
latest
2026.7.1

OpenClaw Discord

Official OpenClaw channel plugin for Discord servers, channels, DMs, slash commands, and app events.

Install from OpenClaw:

openclaw plugin add @openclaw/discord

Configure a Discord bot token and the channels or servers OpenClaw should handle. The plugin lets OpenClaw agents receive Discord messages and respond through the configured Discord app.