Back to skill

Security audit

Bitbucket

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Bitbucket integration, but it should be reviewed because it installs and persistently allowlists an unpinned external plugin with OAuth-backed repository write capabilities.

Before installing, verify the ClawLink plugin publisher and prefer a pinned, reviewed version if available. Connect Bitbucket with the minimum scopes needed, review every preview before approving writes, and be prepared to revoke the OAuth integration or remove the plugin allowlist if anything looks wrong.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Is Installed and Allowlisted

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47-49; related credential-handling context at lines 69-71
Vulnerability Type: Supply-chain risk from an unpinned executable dependency
Risk Level: Medium

The installation instructions contain the following complete command sequence:

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The associated authentication documentation states:

markdown
**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Bitbucket API request on the user's behalf.

Technical Analysis

The Skill instructs the agent to install clawhub:clawlink-plugin without specifying an immutable version, package digest, signature, or other integrity constraint. It then adds the plugin to the OpenClaw tool allowlist and restarts the gateway, causing executable behavior outside the reviewed Skill package to become available to the agent.

Because the referenced plugin implementation is not included in this project, its behavior could not be audited. An unpinned package can resolve to a different implementation after this Skill has been reviewed. If the package distribution account, registry, release process, or latest package version were compromised, the installed plugin could execute attacker-controlled logic.

The Skill uses the plugin to communicate with a hosted intermediary that performs authenticated Bitbucket operations. Consequently, malicious plugin behavior could attempt unauthorized tool calls, alter request parameters, misrepresent responses, or abuse the connected account's repository permissions. The document's requirement for user confirmation before writes is a useful procedural control, but it does not establish the integrity of the plugin that implements or exposes those operations.

Attack Path

  1. An atta ...[truncated 1651 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a reviewed, immutable version rather than installing an unspecified current release.
  2. Verify the package with a cryptographic digest or publisher signature before installation.
  3. Document the expected publisher identity, package provenance, and verification procedure.
  4. Include the plugin source in the audit scope or provide a reproducible build and source-to-package attestation.
  5. Configure the Bitbucket OAuth connection with the minimum repository and write scopes required for the requested task.
  6. Separate read and write capabilities where supported, enabling write permissions only when needed.
  7. Enforce write confirmation outside the plugin itself so a compromised plugin cannot silently bypass that control.
  8. Run the plugin in a restricted sandbox with minimal filesystem, process, network, and credential access.
  9. Monitor authenticated Bitbucket operations and provide users with a clear way to revoke the integration immediately.
  10. Test and review dependency updates before changing the pinned version.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.