Latest release: v2026.7.1Download zip
Compatibility
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The package describes and implements Matrix rooms and direct messages, including sending replies, receiving room/DM events, Matrix media handling, optional encryption support, and account setup.
Instruction Scope
The manifest exposes user-configurable controls for allowlists, group/DM policies, auto-join, private-network homeservers, and Matrix-based approval reactions; these are high-impact options but are disclosed and tied to channel operation.
Install Mechanism
The package is a trusted official @openclaw plugin, source-linked to openclaw/openclaw, with no npm lifecycle scripts or binary entries; OpenClaw runtime/setup entries are declared in the plugin metadata.
Credentials
It reads Matrix-specific environment variables and credentials, connects to configured Matrix homeservers, and can optionally allow private-network homeserver access; this is proportionate for a Matrix integration when configured intentionally.
Persistence & Privilege
It persists Matrix auth/crypto/session/thread/approval state under OpenClaw state paths and includes migration/backup handling for legacy Matrix state; no unrelated persistence or privilege escalation was found.
Scan Findings in Context
[SkillSpector.none] expected: No SkillSpector findings were supplied, so there were no advisory concerns to validate.
[staticScan.clean] expected: Static scan reported no suspicious patterns; local inspection found the sensitive behavior to be Matrix-specific and disclosed.
[VirusTotal.clean] expected: VirusTotal telemetry showed 0 malicious and 0 suspicious detections across 61 engines.
Assessment
Install only with a Matrix account you intend OpenClaw to use. Review room/DM allowlists, auto-join, private-network access, and Matrix approval settings before enabling them, because the plugin can read Matrix messages, send replies/media, and optionally let approved Matrix users resolve exec or plugin approvals.Verification
Tags
OpenClaw Matrix
Official OpenClaw channel plugin for Matrix rooms and direct messages.
Install from OpenClaw:
openclaw plugin add @openclaw/matrix
Configure the Matrix homeserver and bot credentials in OpenClaw. The plugin lets agents join configured rooms, receive messages, and reply through Matrix.
