Scorecard checks whether each webhook configured on the repository has a secret token set so that the receiving service can authenticate the origin of requests. Remediation is to configure the secret where the receiving service supports one, and to ask the service to add token authentication where it does not.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.