Back to skill

Security audit

Nexlink

Security checks for vulnerabilities and agentic risk

Overview

NexLink appears to be a real enterprise connector, but it needs Review because its mail and file integrations use powerful credentials with incomplete safety checks around endpoints, sharing, and local file writes.

Install only after reviewing the connector's access in your own environment. Use dedicated least-privilege Exchange and Nextcloud accounts, require HTTPS endpoints, avoid untrusted local config files, be careful with public share links, and avoid running attachment downloads or destructive file/contact/task operations without checking the exact target.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 Β· Insecure Skill Coding Practices

Error
Location
modules/exchange/connection.py:83
Finding

Exchange Credentials Can Be Transmitted to an Unvalidated Plaintext Endpoint

Content
View full analysis
Remediation
View remediation

T09 Β· Insecure Skill Coding Practices

Error
Location
modules/nextcloud/nextcloud.py:181
Finding

Nextcloud Basic Authentication Credentials Can Be Sent over Plaintext HTTP

Content
View full analysis
None: """Initialize client from environment variables.""" self.url = os.environ.get("NEXTCLOUD_URL", "").rstrip("/") self.username = os.environ.get("NEXTCLOUD_USERNAME", "") self.app_password = os.environ.get("NEXTCLOUD_APP_PASSWORD", "") if not all([self.url, self.username, self.app_password]): raise EnvironmentError( "Missing required environment variables: " "NEXTCLOUD_URL, NEXTCLOUD_USERNAME, NEXTCLOUD_APP_PASSWORD" ) self.auth = HTTPBasicAuth(self.username, self.app_password) self.user_id: str | None = None self._resolve_user_id() def _resolve_user_id(self) -> None: """Resolve the effective user ID from Nextcloud OCS API.""" ocs_url = f"{self.url}/ocs/v1.php/cloud/user" headers = {"OCS-APIRequest": "true"} try: response = requests.get( ocs_url, auth=self.auth, headers=headers, timeout=30, ) ``` The shared request method also attaches the same Basic Authentication credentials to generated URLs: ```python # modules/nextcloud/nextcloud.py:231-243 def _request( self, method: str, url: str, *, operation: str, timeout: int = DEFAULT_TIMEOUT, expected_statuses: set[int] | None = None, **kwargs: Any, ) -> requests.Response | None: """Send an HTTP request and normalize transport errors.""" expected = expected_statuses or {200} try: response = requests.request( method, url, auth=self.auth, ...[truncated 3226 chars]
Remediation
View remediation

T09 Β· Insecure Skill Coding Practices

Error
Location
modules/exchange/mail.py:430
Finding

Untrusted Exchange Attachment Names Can Overwrite Arbitrary Local Files

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (108)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt Β· README.md (reported line 144)May include surrounding context.

md
| Delete contact | `nexlink contacts delete --uid CONTACT_UID --source nextcloud` |
| Search contacts | `nexlink contacts search --source nextcloud --query "Jane"` |
| Create public links | `nexlink files share-create /Contracts/offer.pdf` |
| Delete file / folder | `nexlink files delete /Documents/old` |
| Extract text | `nexlink files extract-text /Clients/contract.docx` |
| Summarize a file | `nexlink files summarize /Clients/contract.docx` |
| Ask a file | `nexlink files ask-file /Clients/contract.docx "When is the renewal due?"` |

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
84% confidence
Finding

The documented delete command accepts a raw path and performs a destructive operation, which creates a tool-parameter abuse risk if an agent passes attacker-influenced or ambiguous input directly into it. In this skill's context, the danger is elevated because the module is designed for remote file management on enterprise Nextcloud data, so misuse can cause irreversible deletion or business disruption.

Content

Scanner excerpt Β· modules/nextcloud/SKILL.md (reported line 119)May include surrounding context.

Delete a file or directory on Nextcloud.

bash
python3 -m modules.nextcloud delete /path/to/delete

move

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt Β· push-commands.sh (reported line 22)May include surrounding context.

sh
*$py.class

# Environment variables (NEVER commit these!)
.env
.env.local
config.yaml
credentials.json

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt Β· push-commands.sh (reported line 23)May include surrounding context.

sh
# Environment variables (NEVER commit these!)
.env
.env.local
config.yaml
credentials.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt Β· push-commands.sh (reported line 25)May include surrounding context.

sh
.env
.env.local
config.yaml
credentials.json

# IDE
.idea/

Known Vulnerable Dependency: lxml==6.0.2 β€” 2 advisory(ies): CVE-2026-41066 (lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to); CVE-2026-41066 (lxml is a library for processing XML and HTML in the Python language. Prior to 6)

High
Category
Supply Chain
Confidence
95% confidence
Finding

The file pins lxml to 6.0.2, which is flagged for XXE-related issues in parser defaults such as iterparse() and ETCompatXMLParser(). Because this skill handles enterprise connectors, document understanding, transcripts, and file management, XML input may come from untrusted remote services or uploaded files, making parser-level XXE flaws particularly relevant for file disclosure, SSRF, or denial of service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises cross-system data movement and outbound communication features such as sending email, downloading attachments, uploading files, sharing content, and moving data between Exchange and Nextcloud, but the documentation does not warn users about privacy, authorization, or operational consequences. In an enterprise connector handling mail, files, tasks, and documents, omission of these warnings can lead to unintended disclosure, accidental exfiltration, or user actions that exceed organizational expectations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document states branding is disabled by default and only enabled via an explicit environment/config opt-in. Later, the checklist says any new public output must verify that the brand line is present, which contradicts the earlier opt-in-only rule and could pressure implementations to include branding even when it should be off.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes NexLink as an enterprise connector for Nextcloud, Exchange, and YouTube, but this branding file defines the headline as 'Exchange, Nextcloud, GitHub β€” one assistant' and says those are the three main integrations. This is an active documentation-level contradiction about the skill's intended scope and integrations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The line states 'RO pentru utilatori romÒni, EN pentru documentație tehnică,' which sets a language policy based on user demographic rather than explicit preference. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation unless clearly documented as a justified regional constraint.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt Β· CHANGELOG.md (reported line 13)May include surrounding context.

md
### Security (ClawScan Findings β€” All Phases)

**Phase 1 β€” Per-command --yes only + Pinned dependencies**
- **Removed session-wide `NEXLINK_AUTO_APPROVE`** β€” `--yes` / `-y` is now strictly **per-command**
  - `utils.confirm_or_die()` no longer checks env var; uses `auto_approved` kwarg only
  - `--yes` must be appended to each individual command; there is no env bypass
  - Nextcloud `run_cli()` uses module-level `_AUTO_APPROVED` instead of env

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt Β· CHANGELOG.md (reported line 16)May include surrounding context.

md
### Security (ClawScan Findings β€” All Phases)

**Phase 1 β€” Per-command --yes only + Pinned dependencies**
- **Removed session-wide `NEXLINK_AUTO_APPROVE`** β€” `--yes` / `-y` is now strictly **per-command**
  - `utils.confirm_or_die()` no longer checks env var; uses `auto_approved` kwarg only
  - `--yes` must be appended to each individual command; there is no env bypass
  - Nextcloud `run_cli()` uses module-level `_AUTO_APPROVED` instead of env

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt Β· CHANGELOG.md (reported line 36)May include surrounding context.

md
### Security (ClawScan Findings β€” All Phases)

**Phase 1 β€” Per-command --yes only + Pinned dependencies**
- **Removed session-wide `NEXLINK_AUTO_APPROVE`** β€” `--yes` / `-y` is now strictly **per-command**
  - `utils.confirm_or_die()` no longer checks env var; uses `auto_approved` kwarg only
  - `--yes` must be appended to each individual command; there is no env bypass
  - Nextcloud `run_cli()` uses module-level `_AUTO_APPROVED` instead of env

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt Β· CHANGELOG.md (reported line 37)May include surrounding context.

md
### Security (ClawScan Findings β€” All Phases)

**Phase 1 β€” Per-command --yes only + Pinned dependencies**
- **Removed session-wide `NEXLINK_AUTO_APPROVE`** β€” `--yes` / `-y` is now strictly **per-command**
  - `utils.confirm_or_die()` no longer checks env var; uses `auto_approved` kwarg only
  - `--yes` must be appended to each individual command; there is no env bypass
  - Nextcloud `run_cli()` uses module-level `_AUTO_APPROVED` instead of env

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt Β· modules/nextcloud/nextcloud.py (reported line 151)May include surrounding context.

python
### Security (ClawScan Findings β€” All Phases)

**Phase 1 β€” Per-command --yes only + Pinned dependencies**
- **Removed session-wide `NEXLINK_AUTO_APPROVE`** β€” `--yes` / `-y` is now strictly **per-command**
  - `utils.confirm_or_die()` no longer checks env var; uses `auto_approved` kwarg only
  - `--yes` must be appended to each individual command; there is no env bypass
  - Nextcloud `run_cli()` uses module-level `_AUTO_APPROVED` instead of env

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt Β· CHANGELOG.md (reported line 14)May include surrounding context.

md
**Phase 1 β€” Per-command --yes only + Pinned dependencies**
- **Removed session-wide `NEXLINK_AUTO_APPROVE`** β€” `--yes` / `-y` is now strictly **per-command**
  - `utils.confirm_or_die()` no longer checks env var; uses `auto_approved` kwarg only
  - `--yes` must be appended to each individual command; there is no env bypass
  - Nextcloud `run_cli()` uses module-level `_AUTO_APPROVED` instead of env
  - Exit code changed from 1 β†’ 2 on non-confirmation

Static analysis

No suspicious patterns detected.