Back to plugin

Security audit

IdentyClaw Tools

Security checks for vulnerabilities and agentic risk

Overview

The package is a coherent IdentyClaw identity and wallet plugin with sensitive but disclosed credential, API-login, and optional wallet capabilities.

Install only if you intend to let OpenClaw use IdentyClaw Passport credentials. Keep private keys out of chat/config where possible, restrict tools.allow carefully, and enable idcp only when you want the agent to perform NEAR/RODiT wallet actions such as funding, transfers, rotation, or activation.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/index.js:789
Evidence
const child = spawn("bash", [scriptPath, ...args], {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/postinstall-generate-near-account.mjs:48
Evidence
const result = spawnSync(process.execPath, [script, defaultDir], {

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:68
Evidence
if (process.env[envName] !== undefined) {