Caveat verdict
identyclaw
IdentyClaw passport and HOLA mutual authentication protocol client; credential access is to user-owned Ed25519 keys for the documented identyclaw.com API, with two clearly separated authentication lanes.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (9)
Possible hardcoded credential
references/login-authentication.md · code · token: "eyJhbGc...
References sudo — requests elevated privileges
references/enrollment.md · code · sudo
Long base64 string (100+ chars) — likely obfuscated payload
references/hola-agent-authentication.md · code · COM/FCHWM6BHKU43A4GB2HO4J455TH3AHAV4WCJJOWBS3VLWSZDRFKR6PYCV7RTPLYABEUY75BOQ4ONO
Uses exec() — may execute shell commands
references/inter-agent-communication.md · code · exec(
References webhook/callback URL
references/openclaw-integration-guide.md · code · webhook_url
Sets world-executable permissions
references/enrollment.md · code · chmod 700
Popular HTTP library — network access
references/hola-agent-authentication.md · code · Got
Makes HTTP request to external URL
references/hola-agent-authentication.md · code · fetch('https://
Opens WebSocket connection
references/hola-agent-authentication.md · prose · downgraded · WebSocket
Permissions & capabilities
No declared permissions — minimal attack surface.
network_outdata_encoding Is this flag fair?
Thanks — recorded.