Security audit
IdentyClaw Webhooks
Security checks across malware telemetry and agentic risk
Overview
The plugin mostly matches its webhook-gateway purpose, but it always registers a debug endpoint that can expose and erase session-linked webhook receipt logs.
Review before installing on a production gateway. Install only if you need IdentyClaw RODiT webhook ingress/outbound delivery, keep NEAR Passport credentials tightly scoped, avoid tlsSkipVerify except in isolated development, and restrict or remove access to /hooks/_receipts so receipt metadata cannot be exposed or cleared unexpectedly.
SkillSpector
By NVIDIA
SkillSpector was not run because this plugin release contains no bundled skills.
VirusTotal
61/61 vendors flagged this plugin as clean.
Static analysis
No suspicious patterns detected.
