Caveat verdict

identyclaw

88
🟢 Trusted
No high-risk patterns surfaced by the deep scan — automated capability review, not behavioral proof.

IdentyClaw passport and HOLA mutual authentication protocol client; credential access is to user-owned Ed25519 keys for the documented identyclaw.com API, with two clearly separated authentication lanes.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

0
security
70
transparency
90
maintenance

Permission integrity

Makes network requests but does not declare curl/wget in required binaries

network_out

Findings (9)

Pattern match critical

Possible hardcoded credential

references/login-authentication.md · code · token: "eyJhbGc...

Pattern match high

References sudo — requests elevated privileges

references/enrollment.md · code · sudo

Pattern match high

Long base64 string (100+ chars) — likely obfuscated payload

references/hola-agent-authentication.md · code · COM/FCHWM6BHKU43A4GB2HO4J455TH3AHAV4WCJJOWBS3VLWSZDRFKR6PYCV7RTPLYABEUY75BOQ4ONO

Pattern match high

Uses exec() — may execute shell commands

references/inter-agent-communication.md · code · exec(

Pattern match medium

References webhook/callback URL

references/openclaw-integration-guide.md · code · webhook_url

Pattern match medium

Sets world-executable permissions

references/enrollment.md · code · chmod 700

Pattern match medium

Popular HTTP library — network access

references/hola-agent-authentication.md · code · Got

Pattern match low

Makes HTTP request to external URL

references/hola-agent-authentication.md · code · fetch('https://

Pattern match low

Opens WebSocket connection

references/hola-agent-authentication.md · prose · downgraded · WebSocket

Permissions & capabilities

No declared permissions — minimal attack surface.

network_outdata_encoding

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API