Back to skill

Security audit

Ahrefs

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Ahrefs SEO integration through ClawLink, with expected credential and network use, but users should understand the external plugin and account access involved.

Install this only if you are comfortable connecting Ahrefs through ClawLink and storing a local ClawLink device credential. Review ClawLink's verification, permissions, and revocation options, and approve write or account-changing actions only after checking the previewed target and scope.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:26
Finding

Unpinned Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 26-28 and 39-43
Vulnerability Type: Supply-chain risk from a mutable, unpinned plugin dependency
Risk Level: Medium

Vulnerable Code

markdown
## Quick start

1. Install the verified ClawLink plugin: `openclaw plugins install clawhub:clawlink-plugin`
markdown
### Installing the plugin

If the ClawLink plugin is not installed yet, tell the user to run:

openclaw plugins install clawhub:clawlink-plugin

Technical Analysis

The Skill instructs users to install clawhub:clawlink-plugin without specifying an immutable version, package digest, signature, or other integrity constraint. The plugin contains executable behavior, but its source is not included in the audited project, which contains only SKILL.md.

Consequently, the code executed by this installation command may differ from the code reviewed when the Skill was published. A compromised publisher account, registry entry, distribution channel, or future malicious update could cause the same documented command to install attacker-controlled code.

The documentation calls the plugin “verified,” but it does not provide a verification procedure or cryptographic identity that users can independently validate.

Attack Path

  1. An attacker compromises the plugin publisher, package registry, release pipeline, or mutable plugin package.
  2. The attacker publishes a malicious release under the existing clawhub:clawlink-plugin identifier.
  3. A user follows the Skill instructions and runs the unpinned installation command.
  4. OpenClaw resolves and installs the attacker-controlled version.
  5. The malicious plugin executes with the permissions available to OpenClaw plugins and can abuse accessible data, credentials, or tools.

This path is conditional on compromise or malicious replacement of the external dependency; the audited file does not itself demonstrate that the current ...[truncated 476 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specific reviewed version and, where supported, an immutable cryptographic digest.
  2. Require signature verification and document the expected publisher identity, signing key, and verification procedure.
  3. Publish the exact plugin source or reproducible build artifact associated with the pinned release.
  4. Document the plugin permissions and reduce them to the minimum required for ClawLink operations.
  5. Configure update behavior so that new versions require explicit review and approval rather than being resolved implicitly.
  6. Add registry-integrity monitoring and a documented rollback procedure for compromised releases.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:47
Finding

Externally Delegated Credential and Dynamic Tool Authority Without Defined Least-Privilege Constraints

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47-66 and 68-86
Vulnerability Type: Excessive or insufficiently constrained authorization delegated to an external integration service
Risk Level: Medium

Vulnerable Code

markdown
### Pairing ClawLink

If ClawLink reports that the plugin is not configured, the plugin has not been paired with the user's ClawLink account yet.

1. Call `clawlink_begin_pairing`.
2. Tell the user to open the returned pairing URL in their browser.
3. The user signs in to ClawLink if needed and approves the OpenClaw device.
4. After the user confirms approval, call `clawlink_get_pairing_status` to finish local setup.

The resulting device credential is stored locally in OpenClaw's plugin config and is only sent to `claw-link.dev`. The user should not paste raw credentials into chat.

### Connecting Ahrefs

Tell the user to open https://claw-link.dev/dashboard?add=ahrefs and connect Ahrefs there. The page opens the add-connection panel filtered to Ahrefs. ClawLink's hosted page runs whichever provider flow is needed (hosted provider setup) — the user follows the hosted provider setup form. When they confirm it is done, call `clawlink_list_integrations` to verify, then call `clawlink_list_tools` with integration `ahrefs`.
markdown
### Execution

1. Call `clawlink_describe_tool` before using an unfamiliar tool, before any write, or when the request is ambiguous.
2. Use the returned schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups`.
3. Prefer read, list, search, and get operations before writes.
4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first, then confirm with the user.
5. Execute with `clawlink_call_tool`.
6. If it fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.

Technical

...[truncated 2749 chars]

Remediation
View remediation

Remediation Suggestions

  1. Document every requested Ahrefs and ClawLink permission and explain why each permission is required.
  2. Default to read-only scopes and require a separate, explicit authorization step before enabling write-capable operations.
  3. Define the device credential lifetime, rotation policy, revocation procedure, and local storage protections.
  4. Store the device credential using the operating system credential store or an equivalently protected secret-management facility rather than general plugin configuration.
  5. Provide users with clear instructions for disconnecting Ahrefs, revoking the paired device, and invalidating compromised credentials.
  6. Constrain the remote tool catalog to a signed, versioned allowlist with a documented maximum capability set.
  7. Enforce write confirmations inside the plugin or service, not solely through natural-language Skill instructions.
  8. Display the exact target, operation, affected objects, and estimated scope during previews, especially for bulk or external-facing actions.
  9. Publish the plugin source, security model, data-retention policy, and an auditable description of credential handling.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes the skill as inspecting backlink, keyword, ranking, and SEO research data, which implies read-oriented analysis. However, the execution guidance explicitly anticipates writes, confirmations for destructive or bulk write actions, and account-changing operations, indicating the skill may be used for modifying external Ahrefs-connected resources beyond the stated inspection scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The capability summary focuses on looking up, inspecting, reviewing, and pulling reporting data, which presents the skill as an analytics/research interface. Yet nearby rules instruct the agent to ask for confirmation before destructive, external-facing, or bulk write actions, implying materially broader capabilities than the stated SEO inspection purpose.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
## Rules

- Always use ClawLink tools for Ahrefs. Do not ask the user for separate Ahrefs credentials.
- Do not claim a capability is missing without checking the live ClawLink catalog in the current turn.
- Do not invent slash commands or ask the user to paste raw credentials.
- Ask for confirmation before destructive, external-facing, or bulk write actions.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
## Rules

- Always use ClawLink tools for Ahrefs. Do not ask the user for separate Ahrefs credentials.
- Do not claim a capability is missing without checking the live ClawLink catalog in the current turn.
- Do not invent slash commands or ask the user to paste raw credentials.
- Ask for confirmation before destructive, external-facing, or bulk write actions.
- If Ahrefs is not connected, direct the user to https://claw-link.dev/dashboard?add=ahrefs.

Static analysis

No suspicious patterns detected.