Back to skill

Security audit

Box

Security checks for vulnerabilities and agentic risk

Overview

This Box skill is coherent and disclosed, but it asks users to activate an unpinned third-party plugin that can perform high-impact Box account actions.

Review the ClawLink plugin and publisher trust before installing. Prefer a pinned or verified plugin release if available, connect only the Box account with the minimum permissions needed, and be especially careful with collaboration, deletion, user/group, retention, legal-hold, and signature-request actions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Privileged Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–49
Vulnerability Type: Unpinned third-party dependency with privileged tool access
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The skill instructs users to install clawlink-plugin from ClawHub without specifying an immutable version, cryptographic digest, or signature-verification procedure. It then explicitly adds the plugin to the OpenClaw tool allowlist and restarts the gateway, activating whichever package the registry serves at installation time.

The audited project contains no plugin source, lockfile, checksum, signature metadata, or reproducible-build information with which to verify the executable dependency. Consequently, the effective implementation can change independently of the reviewed SKILL.md file.

This creates a supply-chain trust gap. If the package registry, publisher account, distribution channel, or a later mutable release is compromised, malicious code could be delivered under the expected package name and receive the documented tool access after restart.

Attack Path

  1. An attacker compromises the ClawHub package entry, the publisher account, or the plugin distribution channel.
  2. The attacker publishes a modified package under the existing clawlink-plugin identifier.
  3. A user follows the skill’s unpinned installation command.
  4. OpenClaw downloads the attacker-controlled package because no immutable version or digest is required.
  5. The user’s configuration allowlists the plugin.
  6. The gateway restart loads and activates the compromised plugin.
  7. The plugin abuses its tool access or OAuth-mediated Box connection to perform unauthorized operations within the connected account’s permissions.

Impact Assessment

A compromised plugin could operate with the OpenClaw tool acc ...[truncated 773 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a reviewed, immutable version rather than installing the floating package identifier.
  2. Require verification against a cryptographic digest or trusted publisher signature before installation.
  3. Publish the plugin source, dependency lockfile, release checksums, and reproducible-build instructions so the installed artifact can be independently audited.
  4. Enforce registry protections such as publisher identity verification, protected releases, multi-factor authentication, and signed provenance attestations.
  5. Grant only the minimum OpenClaw tools required for Box operations instead of broadly trusting the plugin.
  6. Separate read-only and write-capable permissions where possible, and keep destructive or administrative Box operations disabled unless explicitly needed.
  7. Present a clear security prompt before installation, allowlisting, gateway restart, and Box authorization.
  8. Monitor plugin-version changes and require renewed review and approval before upgrades.
  9. Provide a documented revocation procedure covering plugin removal, allowlist cleanup, OAuth-token revocation, and Box audit-log review.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.