Back to plugin

Security audit

OpenClaw A2A Plugin

Security checks for vulnerabilities and agentic risk

Overview

This package is a disclosed OpenClaw A2A messaging plugin that uses peer authentication, local state, and optional audit logs in ways that match its stated purpose.

Install this only if you intend to let OpenClaw send or receive A2A peer messages. Configure JWT audience/issuer or API keys carefully, avoid auth.provider none or allowUnauthenticated except in trusted environments, and use tlsSkipVerify only for trusted self-signed peer networks. Enable audit logging only if you are comfortable storing message summaries locally.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
dist/outbound/tls-fetch.js:19
Evidence
rejectUnauthorized: false,