Bluebubbles
Alert level: High
Build or update the BlueBubbles external channel plugin for Clawdbot (extension package, REST send/probe, webhook inbound).
Locality:Hybrid
Data access:Sensitive
Actions:Write
Installs 23Downloads 156Stars 0Updated 373h ago
Why this rating
Deterministic checks triggered by the tool capabilities and evidence.
- Locality: Hybrid
Config includes a BlueBubbles 'serverUrl' and webhook endpoint for HTTP traffic.
- Data access: Sensitive
Handles messages and inbound attachments via webhooks and download helpers.
- Action surface: Write
Can send messages, reactions, typing indicators, and mark chats read.
Best practices
Follow these steps to reduce risk when using this skill.
- Restrict the BlueBubbles server/webhook to trusted networks or VPN access.
- Store the BlueBubbles password in a secret manager and rotate it regularly.
- Limit which chats/targets the plugin can message to reduce accidental disclosure.
Evidence links
Public sources backing the indicator assignments.
Always be careful when navigating away from the website.
Max-risk rule
If any capability reaches a higher level, the entire indicator level bumps up to keep ratings deterministic and easy to scan.