
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
openclaw-plugin-yuanbao
Advanced tools
summary: "Yuanbao bot overview, features, and configuration" read_when:
Tencent Yuanbao is Tencent's AI assistant platform. The OpenClaw channel plugin connects Yuanbao bots to OpenClaw over WebSocket so they can interact with users through direct messages and group chats.
Status: production-ready for bot DMs + group chats. WebSocket is the only supported connection mode.
Requires OpenClaw 2026.5.7 or above. Run
openclaw --versionto check. Upgrade withopenclaw update.
openclaw channels add --channel yuanbao --token "appKey:appSecret"
The --token value uses colon-separated appKey:appSecret format. You can obtain these from the Yuanbao app by creating a robot in your application settings.
openclaw gateway restart
You can also use the interactive wizard:
openclaw channels login --channel yuanbao
Follow the prompts to enter your App ID and App Secret.
Configure dmPolicy to control who can DM the bot:
"pairing" — unknown users receive a pairing code; approve via CLI"allowlist" — only users listed in allowFrom can chat"open" — allow all users (default)"disabled" — disable all DMsApprove a pairing request:
openclaw pairing list yuanbao
openclaw pairing approve yuanbao <CODE>
Mention requirement (channels.yuanbao.requireMention):
true — require @mention (default)false — respond without @mentionReplying to the bot's message in a group chat is treated as an implicit mention.
{
channels: {
yuanbao: {
appKey: "your_app_key",
appSecret: "your_app_secret",
dm: {
policy: "open",
},
},
},
}
{
channels: {
yuanbao: {
appKey: "your_app_key",
appSecret: "your_app_secret",
dm: {
policy: "allowlist",
allowFrom: ["user_id_1", "user_id_2"],
},
},
},
}
{
channels: {
yuanbao: {
requireMention: false,
},
},
}
{
channels: {
yuanbao: {
// Send each chunk immediately without buffering
outboundQueueStrategy: "immediate",
},
},
}
{
channels: {
yuanbao: {
outboundQueueStrategy: "merge-text",
minChars: 2800, // buffer until this many chars
maxChars: 3000, // force split above this limit
idleMs: 5000, // auto-flush after idle timeout (ms)
},
},
}
| Command | Description |
|---|---|
/help | Show available commands |
/status | Show bot status |
/new | Start a new session |
/stop | Stop the current run |
/restart | Restart OpenClaw |
/compact | Compact the session context |
Yuanbao supports native slash-command menus. Commands are synced to the platform automatically when the gateway starts.
openclaw logs --followappKey and appSecret are correctly configuredopenclaw gateway statusopenclaw logs --followchannels.yuanbao.fallbackReplyopenclaw gateway restart{
channels: {
yuanbao: {
defaultAccount: "main",
accounts: {
main: {
appKey: "key_xxx",
appSecret: "secret_xxx",
name: "Primary bot",
},
backup: {
appKey: "key_yyy",
appSecret: "secret_yyy",
name: "Backup bot",
enabled: false,
},
},
},
},
}
defaultAccount controls which account is used when outbound APIs do not specify an accountId.
maxChars — single message max character count (default: 3000 chars)mediaMaxMb — media upload/download limit (default: 20 MB)overflowPolicy — behavior when message exceeds limit: "split" (default) or "stop"Yuanbao supports block-level streaming output. When enabled, the bot sends text in chunks as it generates.
{
channels: {
yuanbao: {
disableBlockStreaming: false, // block streaming enabled (default)
},
},
}
Set disableBlockStreaming: true to send the complete reply in one message.
Control how many historical messages are included in the AI context for group chats:
{
channels: {
yuanbao: {
historyLimit: 100, // default: 100, set 0 to disable
},
},
}
Control how the bot quotes messages when replying in group chats:
{
channels: {
yuanbao: {
replyToMode: "first", // "off" | "first" | "all" (default: "first")
},
},
}
| Value | Behavior |
|---|---|
"off" | No quote reply |
"first" | Quote only the first reply per inbound message (default) |
"all" | Quote every reply |
By default, the bot injects instructions in the system prompt to prevent the AI model from wrapping the entire reply in markdown code blocks.
{
channels: {
yuanbao: {
markdownHintEnabled: true, // default: true
},
},
}
Enable unsanitized log output for specific bot IDs:
{
channels: {
yuanbao: {
debugBotIds: ["bot_user_id_1", "bot_user_id_2"],
},
},
}
Use bindings to route Yuanbao DMs or groups to different agents.
{
agents: {
list: [
{ id: "main" },
{ id: "agent-a", workspace: "/home/user/agent-a" },
{ id: "agent-b", workspace: "/home/user/agent-b" },
],
},
bindings: [
{
agentId: "agent-a",
match: {
channel: "yuanbao",
peer: { kind: "direct", id: "user_xxx" },
},
},
{
agentId: "agent-b",
match: {
channel: "yuanbao",
peer: { kind: "group", id: "group_zzz" },
},
},
],
}
Routing fields:
match.channel: "yuanbao"match.peer.kind: "direct" (DM) or "group" (group chat)match.peer.id: user ID or group codeFull configuration: Gateway configuration
| Setting | Description | Default |
|---|---|---|
channels.yuanbao.enabled | Enable/disable the channel | true |
channels.yuanbao.defaultAccount | Default account for outbound routing | default |
channels.yuanbao.accounts.<id>.appKey | App Key (used for signing and ticket generation) | — |
channels.yuanbao.accounts.<id>.appSecret | App Secret (used for signing) | — |
channels.yuanbao.accounts.<id>.token | Pre-signed token (skips automatic ticket signing) | — |
channels.yuanbao.accounts.<id>.name | Account display name | — |
channels.yuanbao.accounts.<id>.enabled | Enable/disable a specific account | true |
channels.yuanbao.dm.policy | DM policy | open |
channels.yuanbao.dm.allowFrom | DM allowlist (user ID list) | — |
channels.yuanbao.requireMention | Require @mention in groups | true |
channels.yuanbao.overflowPolicy | Long message handling (split or stop) | split |
channels.yuanbao.replyToMode | Group reply-to strategy (off, first, all) | first |
channels.yuanbao.outboundQueueStrategy | Outbound strategy (merge-text or immediate) | merge-text |
channels.yuanbao.minChars | Merge-text: min chars to trigger send | 2800 |
channels.yuanbao.maxChars | Merge-text: max chars per message | 3000 |
channels.yuanbao.idleMs | Merge-text: idle timeout before auto-flush (ms) | 5000 |
channels.yuanbao.mediaMaxMb | Media size limit (MB) | 20 |
channels.yuanbao.historyLimit | Group chat history context entries | 100 |
channels.yuanbao.disableBlockStreaming | Disable block-level streaming output | false |
channels.yuanbao.fallbackReply | Fallback reply when AI returns no content | 暂时无法解答,你可以换个问题问问我哦 |
channels.yuanbao.markdownHintEnabled | Inject markdown anti-wrapping instructions | true |
channels.yuanbao.debugBotIds | Debug whitelist bot IDs (unsanitized logs) | [] |
replyToMode)FAQs
Tencent YuanBao intelligent bot channel plugin
The npm package openclaw-plugin-yuanbao receives a total of 1,058 weekly downloads. As such, openclaw-plugin-yuanbao popularity was classified as popular.
We found that openclaw-plugin-yuanbao demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.