Security audit
IdentyClaw Webhooks
Security checks across malware telemetry and agentic risk
Overview
This plugin coherently provides signed IdentyClaw webhook ingress and outbound webhook delivery, with sensitive behavior disclosed and scoped to that purpose.
Install this only on an OpenClaw gateway intended to receive IdentyClaw/RODiT webhooks. Keep NEAR Passport credentials in secrets, expose the webhook routes only behind appropriate TLS/network controls, leave enableReceiptsEndpoint off outside local debugging, and allow send_rodit_webhook only in sandboxes where outbound peer messaging is intended.
SkillSpector was not run because this plugin release contains no bundled skills.
VirusTotal
60/60 vendors flagged this plugin as clean.
Static analysis
No suspicious patterns detected.
