Back to skill

Security audit

Canva

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Canva integration that relies on the ClawLink plugin and OAuth, with no hidden or malicious behavior found.

Before installing, confirm you trust ClawLink to mediate Canva access, review the Canva permissions granted during OAuth, and be aware that the plugin install and allowlist change persist beyond the current chat.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:54
Finding

Unpinned Privileged Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14, 54–58, 73–80, and 111–112
Vulnerability Type: Unpinned third-party dependency with privileged OAuth-mediated access
Risk Level: Medium

The skill instructs the agent to install and explicitly allowlist a third-party plugin without pinning an immutable version or integrity hash:

markdown
This skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=canva-designs) for hosted connection flows and credentials so you do not need to configure Canva API access yourself.
bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The installed component is then entrusted with OAuth credentials and authenticated API requests:

markdown
All Canva tool calls are authenticated automatically by ClawLink using the user's connected Canva account.

**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Canva API request on the user's behalf.

The effective tool interface is also obtained dynamically:

markdown
Tools are available dynamically from the live ClawLink catalog. Call `clawlink_list_tools --integration canva` to see the full list.

Technical Analysis

The installation command identifies the plugin only as clawhub:clawlink-plugin; it does not specify a fixed version, immutable package digest, signature requirement, or checksum. The plugin is subsequently added to the tool allowlist and loaded by restarting the gateway.

This creates a supply-chain trust boundary that is not fully represented by the auditable project contents. The installed plugin can participate in authenticated Canva operations, while the remotely supplied live catalog determines which tools are exposed. Although the document describes ClawLink as verified and states that tokens are stored securely, the proje ...[truncated 2209 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a reviewed, immutable version rather than installing a floating package identifier.
  2. Verify the package using a cryptographic digest and publisher signature before installation.
  3. Publish or reference reproducible, reviewable source code for the exact plugin release.
  4. Document the plugin's local permissions, network destinations, OAuth scopes, token-storage model, and update behavior.
  5. Request only the minimum Canva OAuth scopes needed for the user's requested operation.
  6. Require explicit, informed user approval before installing the plugin, changing the tool allowlist, restarting the gateway, or initiating OAuth delegation.
  7. Avoid automatically completing installation and restart steps merely because the skill was invoked.
  8. Constrain the dynamic tool catalog to an approved set of Canva operations and reject newly introduced tools until reviewed.
  9. Isolate the plugin with least-privilege filesystem, process, and network permissions.
  10. Provide a revocation procedure covering Canva authorization, ClawLink pairing, plugin removal, and token invalidation.
  11. Record and surface the exact plugin version and integrity metadata in audit logs.
  12. Re-review the plugin and its exposed tool catalog before accepting updates.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.