Back to skill

Security audit

ActiveCampaign

Security checks for vulnerabilities and agentic risk

Overview

This skill is Review-worthy because it installs and persistently allowlists an external OAuth-backed plugin while giving some direct write examples that conflict with its own confirmation requirement.

Install only if you trust the ClawLink plugin and publisher, are comfortable connecting an ActiveCampaign account through OAuth, and will require preview plus explicit approval for every create, update, delete, webhook, connection, bulk import, or bulk delete action. Consider checking the plugin version and removal path before enabling it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Installation and Allowlisting

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–49
Vulnerability Type: Unpinned and externally maintained plugin dependency
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The permission change and restart are also repeated in SKILL.md, lines 296–297:

bash
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The skill instructs users to install clawhub:clawlink-plugin without selecting an immutable version or verifying a package signature, checksum, or source revision. It then explicitly allowlists the plugin and restarts the gateway, causing the externally maintained component to be loaded with plugin capabilities.

Because this repository contains only SKILL.md, the plugin implementation and its credential-handling behavior are outside the audited scope. The mutable package reference means that code retrieved during a future installation may differ from the code originally reviewed. This creates a supply-chain trust boundary in which compromise of the package, publisher account, distribution service, or dependency resolution process could deliver unauthorized code.

The documentation also states that ClawLink stores an OAuth token and injects it into ActiveCampaign requests. This is transparent rather than hidden behavior, but it increases the potential consequences of a compromised plugin.

Attack Path

  1. An attacker compromises the plugin publisher account, package-distribution channel, or an upstream component used by the plugin.
  2. The attacker publishes a malicious release under the mutable clawhub:clawlink-plugin identifier.
  3. A user follows the skill instructions and installs the package without an immutable version or integrity verification.

...[truncated 1037 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an audited, immutable version or content-addressed revision rather than installing a mutable package identifier.
  2. Verify a cryptographic signature or publisher-provided checksum before installation.
  3. Document the expected publisher identity, package version, digest, and trusted distribution origin.
  4. Publish or vendor the exact plugin source so its code, dependencies, network behavior, and credential handling can be independently audited.
  5. Apply least privilege by allowing only the specific tools required for ActiveCampaign tasks rather than broadly enabling the entire plugin where the platform supports granular controls.
  6. Require explicit user approval before installation, configuration modification, gateway restart, OAuth connection, and sensitive write operations.
  7. Isolate the plugin process and restrict filesystem, environment-variable, network, and credential access to the minimum necessary.
  8. Maintain dependency scanning, release signing, provenance attestations, and a documented revocation process for compromised releases.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description frames the skill as an ActiveCampaign marketing-management skill focused on common CRM and marketing objects. However, the documented capabilities also include activecampaign_create_webhook and activecampaign_create_connection, which extend into platform integration and outbound event plumbing rather than the stated core marketing-management scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The stated purpose focuses on contacts, campaigns, automations, lists, deals, and pipelines. The documented tool reference adds e-commerce and event-tracking capabilities such as creating orders, customers, tracking carts, and whitelisting event names, which are materially outside the manifest's described scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that all write operations require explicit user confirmation, yet the quick-start section demonstrates direct execution of write tools without a preview or confirmation gate. In an agent setting, examples strongly influence behavior, so this inconsistency can lead to unintended contact, list, campaign, or workflow modifications without the promised safety check.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.