Back to skill

Security audit

Amplitude

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Amplitude analytics purpose is coherent, but it asks users to enable an unpinned third-party plugin that handles Amplitude credentials and can perform high-impact analytics writes or deletions.

Before installing, verify the ClawLink plugin publisher and version through a trusted source, use a dedicated least-privilege Amplitude credential, and understand that ClawLink will store and inject that API key. Keep write/delete operations opt-in and carefully confirm previews, especially GDPR/CCPA deletion, user mapping, and cohort changes. Remove the plugin or revoke the Amplitude key if you no longer need the integration.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Is Granted Access to Credentials and Analytics Operations

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–49; related credential-flow context at lines 71–77
Vulnerability Type: Unpinned third-party dependency with privileged integration access
Risk Level: Medium

Complete Code Snippet:

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Related credential-flow instructions:

markdown
**No API key is required in chat.** ClawLink stores the API key securely and injects it into every Amplitude API request on the user's behalf.

### Getting Connected

1. Install the ClawLink plugin (see Install above).
2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.
3. Open https://claw-link.dev/dashboard?add=amplitude and connect Amplitude.
4. Call `clawlink_list_integrations` to verify the connection is active.

Technical Analysis

The Skill instructs users to install clawhub:clawlink-plugin without pinning a version, immutable digest, or other verifiable artifact identifier. It then immediately adds that plugin to the OpenClaw tool allowlist and restarts the gateway so the component becomes active.

The enabled component is trusted to participate in a hosted credential flow. According to the Skill, ClawLink stores the user's Amplitude API key and injects it into requests. The repository contains only SKILL.md; it does not include the plugin implementation, a dependency lockfile, a checksum, signature-verification instructions, or other material that would allow the installed artifact to be matched to an audited version. The document's statement that the plugin is “verified” is therefore not independently substantiated by the reviewed project contents.

This creates a supply-chain trust boundary: the code that ultimately runs and handles credentials may change after this Skill has been reviewed. Exploitation requir ...[truncated 1984 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a reviewed, immutable version and cryptographic digest instead of installing only by a mutable package name.
  2. Require package-signature and provenance verification before installation, and document the expected publisher identity and artifact hash.
  3. Include or link to auditable source corresponding exactly to the pinned release. Maintain a lockfile or manifest recording the verified artifact.
  4. Separate installation, allowlisting, and activation steps. Display the permissions and affected trust boundaries, then obtain informed user approval before enabling or restarting the gateway.
  5. Use a dedicated, least-privilege Amplitude credential restricted to the required project and operations. Avoid administrative or destructive permissions when only analytics reads are needed.
  6. Make write and destructive tools opt-in rather than granting them by default. Enforce confirmation outside the third-party plugin where possible.
  7. Document ClawLink's credential storage, encryption, retention, revocation, data-processing, and incident-response controls so users can evaluate the external processor.
  8. Support rapid credential revocation and plugin rollback. Rotate Amplitude credentials after suspected package or service compromise.
  9. Log plugin installation, tool invocation, credential use, and sensitive Amplitude operations to an independently protected audit destination.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.