Back to skill

Security audit

intercom-conversations

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only Intercom conversations skill with expected token use; the main cautions are sensitive conversation data handling and dependency hygiene, not evidence of malicious behavior.

Before installing, use a least-privilege Intercom token and be careful about what conversation data you ask the agent to retrieve, because customer support content may become part of the agent context. Prefer installing with a lockfile or exact vetted dependency version for reproducibility.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · clawhub.skill.json (reported line 16)May include surrounding context.

json
{
      "name": "INTERCOM_ACCESS_TOKEN",
      "required": true,
      "description": "Intercom Personal Access Token / OAuth access token."
    }
  ],
  "actions": [

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · clawhub.skill.json (reported line 16)May include surrounding context.

json
{
      "name": "INTERCOM_ACCESS_TOKEN",
      "required": true,
      "description": "Intercom Personal Access Token / OAuth access token."
    }
  ],
  "actions": [

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that an Intercom access token is required and describes actions that list, find, and search conversations, but it does not explicitly warn users that the skill will transmit that token and potentially sensitive conversation data to the external Intercom API. Because conversation content may include customer support messages and other sensitive business data, lack of clear disclosure can lead to uninformed use and inadvertent data exposure outside the local agent environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description says it is invoked as default(input), which indicates a broad default trigger without any documented activation constraints, user-consent gates, or narrowing conditions. In a read-capable Intercom conversations skill, this increases the chance that an agent may call it opportunistically and retrieve sensitive customer support conversation data without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is specified with a caret range (^6.0.0), which allows newer 6.x releases to be installed without review. In a security-sensitive integration skill that reads customer conversations from Intercom, this increases supply-chain risk because a later compromised or vulnerable minor/patch release could be pulled in during installation.

Content

Scanner excerpt · package.json (reported line 20)May include surrounding context.

json
"node": ">=18"
  },
  "dependencies": {
    "intercom-client": "^6.0.0"
  },
  "license": "MIT",
  "private": true

Unverifiable Dependency: intercom-client has 2 known advisory(ies) (GHSA-54pg-9963-v8vg (Compromised version of intercom-client published to npm); MAL-2026-3204 (Malicious code in intercom-client (npm))), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest references intercom-client without pinning to a specific vetted release, while the package has known advisories including reports of compromised/malicious published versions. Because this skill accesses Intercom conversation data, installing an affected version could expose sensitive customer communications or execute attacker-controlled code in the skill environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.