Security audit
Agent Passport System
Security checks for vulnerabilities and agentic risk
Overview
This package is a disclosed OpenClaw trust-verification plugin with sensitive signing features disabled by default and scoped by explicit configuration.
Review the README limitations before relying on this as an enforcement layer. Keep signing disabled unless you intentionally want this host to sign messages with an APS passport, and if you enable it, use a limited-purpose passport and a narrow allowedCallers list rather than gateway-client unless all authenticated gateway clients are trusted.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
