Back to skill

Security audit

Datadog

Security checks for vulnerabilities and agentic risk

Overview

This Datadog skill is mostly transparent about using ClawLink, but it asks users to install an external plugin and authorize broad Datadog access, including sensitive reads and destructive writes, without enough scoping guidance.

Review the ClawLink plugin and Datadog OAuth scopes before installing. Prefer a dedicated, least-privilege Datadog account, avoid full-permission reconnects unless you truly need write operations, and treat logs, traces, users, roles, API-key metadata, webhooks, incidents, monitors, and host data as confidential.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned Third-Party Plugin Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:29-34
Vulnerability Type: Unpinned third-party plugin installation
Risk Level: Medium

Technical Analysis

The setup instructions require installation of a third-party plugin by a mutable registry identifier, without specifying a version, integrity hash, verified publisher identity, or reviewed source revision:

markdown
**Step 1** — Install the ClawLink plugin:
text
openclaw plugins install clawhub:clawlink-plugin
markdown
Start a fresh chat after installing.

Installing clawhub:clawlink-plugin by name means the code obtained at installation time can differ from the code originally reviewed. The instruction to start a fresh chat indicates that the plugin is loaded into subsequent agent sessions and exposes additional clawlink_* tools.

No malicious plugin implementation is present in the audited project, and the audit therefore does not establish that the current package is malicious. The weakness is that this skill delegates security-sensitive behavior to an externally distributed, unpinned component without providing an integrity control.

Attack Path

  1. An attacker compromises the plugin publisher account, registry entry, distribution infrastructure, or another part of the plugin supply chain.
  2. The attacker publishes a modified release under the same mutable clawhub:clawlink-plugin identifier.
  3. A user follows the documented installation command.
  4. OpenClaw downloads and installs the modified plugin without validating it against a version or digest specified by this skill.
  5. The user starts a fresh chat, causing the installed plugin and its tools to become available.
  6. Malicious plugin code can then act with whatever local access and integration privileges the OpenClaw plugin runtime grants it.

Impact Assessment

A compromised plugin could potentially access local plugin configuration, device credenti ...[truncated 491 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the plugin to an explicitly reviewed immutable version.
  • Where supported, include and verify a cryptographic package digest or signature.
  • Link to the exact source revision corresponding to the installed artifact.
  • Require signed releases from a verified publisher and document how users can verify the signature.
  • Avoid automatic upgrades to unreviewed releases.
  • Run the plugin in a restricted sandbox with minimal filesystem, network, process, and credential access.
  • Document the plugin's requested permissions before installation.
  • Maintain a reviewed lockfile or equivalent installation manifest so future installations resolve to the same artifact.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:107
Finding

Broad Datadog Write Capabilities and Full-Permission Reauthorization Exceed the Stated Inspection Scope

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:107-124, with related scope guidance at SKILL.md:230-233
Vulnerability Type: Excessive integration privileges and violation of least privilege
Risk Level: High

Technical Analysis

The skill is described primarily as an inspection capability, but it exposes numerous state-changing and destructive Datadog operations:

markdown
### Write operations

| Tool | Description | Risk |
|------|-------------|------|
| `datadog_create_dashboard` | Create a customizable monitoring dashboard | confirm |
| `datadog_create_downtime` | Suppress alerts during maintenance windows | confirm |
| `datadog_create_event` | Track deployments, outages, configuration changes | confirm |
| `datadog_create_monitor` | Create a monitor with alerting thresholds and notifications | confirm |
| `datadog_create_slo` | Create a Service Level Objective for reliability tracking | confirm |
| `datadog_create_synthetic_api_test` | Create a synthetic API test from multiple global locations | confirm |
| `datadog_create_webhook` | Register a webhook endpoint for monitor notifications | confirm |
| `datadog_delete_dashboard` | Permanently remove a dashboard | high_impact |
| `datadog_delete_monitor` | Permanently delete a monitor | high_impact |
| `datadog_mute_monitor` | Temporarily silence alerts (maintenance windows) | confirm |
| `datadog_submit_metrics` | Submit custom metrics and business KPIs | confirm |
| `datadog_unmute_monitor` | Re-enable alerts from a previously muted monitor | confirm |
| `datadog_update_dashboard` | Update dashboard configuration, widgets, or layout | confirm |
| `datadog_update_host_tags` | Replace all tags on a specific host | confirm |
| `datadog_update_monitor` | Update monitor thresholds or notification settings | confirm |

The troubleshooting guidance additionally recommends reconnecting with full permissions when a requested scope is unava ...[truncated 2928 chars]

Remediation
View remediation

Remediation Suggestions

  • Make the default Datadog connection read-only and request only scopes required for monitor, metric, log, trace, incident, and dashboard inspection.
  • Remove the recommendation to reconnect with “full permissions.” Instead, identify the exact missing scope and explain why it is necessary.
  • Separate read and write functionality into distinct integrations or explicit authorization profiles.
  • Request write scopes incrementally and only immediately before a user-requested write operation.
  • Require an explicit, operation-specific confirmation that displays the target resource, account, parameters, and expected consequences.
  • Require stronger confirmation for destructive operations such as monitor or dashboard deletion.
  • Disable webhook creation, monitor muting, host-tag replacement, and deletion tools unless the user explicitly enables those capabilities.
  • Enforce tool allowlists and authorization checks in the plugin or service rather than relying solely on descriptive risk labels in documentation.
  • Use short-lived OAuth tokens, support prompt revocation, and record auditable logs for every state-changing call.
  • Document the exact OAuth scopes associated with each tool so users can make an informed authorization decision.
  • Where possible, use a dedicated Datadog service account restricted to selected resources rather than an organization-wide privileged account.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises numerous read-only Datadog operations as 'safe' even though they can expose sensitive operational and organizational data, including hosts, logs, incidents, users, roles, API key metadata, webhooks, dashboards, and traces. Without an explicit warning in the skill description or security section that these reads may reveal confidential infrastructure, personnel, and incident information, users may authorize or invoke the skill with insufficient awareness of the disclosure risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.