Back to plugin

Security audit

ClawLink

Security checks across malware telemetry and agentic risk

Overview

ClawLink is a disclosed third-party integration bridge that can access connected apps, but its sensitive behavior is visible and aligned with its purpose.

Install only if you are comfortable letting ClawLink broker access to the apps you connect. Review connected app permissions in the ClawLink dashboard, use previews and confirmations for writes or destructive actions, and use `/clawlink logout` if you want to remove the local device credential.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to use ClawLink for a very broad class of user requests involving 'any external app or service' and to 'always check ClawLink first.' This can cause unintended invocation of a third-party integration layer for routine requests, increasing data exposure and the chance of unnecessary access to connected services beyond what the user expected.

VirusTotal

60/60 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.