Back to skill

Security audit

Airtable

Security checks for vulnerabilities and agentic risk

Overview

This Airtable skill is coherent, but it asks users to trust an unpinned external plugin that handles OAuth-backed Airtable access and can change or delete data.

Review the ClawLink plugin and its requested Airtable scopes before installing. Use an Airtable account with the narrowest practical access, confirm every write or delete carefully, and know how to remove the plugin and revoke Airtable OAuth access if you stop using it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Is Granted Trusted Tool Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–49; repeated configuration commands at lines 290–291
Vulnerability Type: Unpinned third-party dependency with privileged integration access
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The relevant configuration and restart operations are repeated later:

bash
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The skill directs the user or agent to install clawhub:clawlink-plugin without pinning a reviewed version or cryptographic digest. It then adds the plugin to OpenClaw's tool allowlist and restarts the gateway so that the plugin becomes active.

This creates a supply-chain trust boundary: the effective implementation is obtained separately from the audited skill and may change after this file has been reviewed. The project does not include the plugin source, an integrity hash, a locked version, or a permission manifest that would allow its behavior to be verified as part of this audit.

The plugin's access is security-sensitive because the skill states that ClawLink stores the user's Airtable OAuth token, injects it into API requests, and proxies those requests. Consequently, an unexpectedly changed or compromised plugin release could operate within the user's OAuth-authorized Airtable scope.

Attack Path

  1. An attacker compromises the plugin publisher account, package registry entry, distribution infrastructure, or another component of the plugin's supply chain.
  2. The attacker publishes a malicious release under the mutable clawlink-plugin identifier.
  3. A user follows the skill instructions and installs the plugin without a fixed version or integrity check.
  4. The configuration command adds the plugin to the trusted tool allowlist.
  5. Restartin ...[truncated 1434 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specifically reviewed, immutable version rather than installing a mutable package identifier.
  2. Verify the package with a publisher signature or cryptographic digest before installation.
  3. Publish and review the corresponding source code, build provenance, release artifacts, and software bill of materials.
  4. Present a permission manifest before installation that identifies local capabilities, network destinations, credential access, and available Airtable operations.
  5. Require separate, explicit user approval before installing the plugin, modifying the tool allowlist, or restarting the gateway.
  6. Apply least privilege to both OpenClaw tool permissions and Airtable OAuth scopes. Avoid granting schema modification or destructive-operation scopes unless required.
  7. Restrict network communication to documented ClawLink and Airtable endpoints where the platform supports egress controls.
  8. Preserve confirmation enforcement outside the plugin so a plugin cannot unilaterally bypass approval for write or destructive operations.
  9. Document how to revoke Airtable OAuth access, unpair ClawLink, remove the allowlist entry, uninstall the plugin, and rotate affected credentials.
  10. Re-audit every plugin update before changing the pinned version.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.