Security audit
IdentyClaw Webhooks
Security checks for vulnerabilities and agentic risk
Overview
This plugin does what it advertises: it adds signed IdentyClaw webhook endpoints and an outbound signed-webhook tool, with sensitive access disclosed and scoped to that purpose.
Install this only on a gateway meant to receive IdentyClaw/RODiT signed webhooks. Keep NEAR Passport credentials in secrets as documented, expose /hooks/* only behind TLS, leave the receipts endpoint and peer-registry persistence disabled unless needed for debugging, and enable the outbound tool only for agents that should be allowed to send signed webhooks to peers.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
