Back to plugin

Security audit

IdentyClaw Webhooks

Security checks across malware telemetry and agentic risk

Overview

The plugin mostly matches its webhook-gateway purpose, but it always registers a debug endpoint that can expose and erase session-linked webhook receipt logs.

Review before installing on a production gateway. Install only if you need IdentyClaw RODiT webhook ingress/outbound delivery, keep NEAR Passport credentials tightly scoped, avoid tlsSkipVerify except in isolated development, and restrict or remove access to /hooks/_receipts so receipt metadata cannot be exposed or cleared unexpectedly.

SkillSpector

By NVIDIA

SkillSpector was not run because this plugin release contains no bundled skills.

VirusTotal

61/61 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.