Back to skill

Security audit

DataForSEO

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its DataForSEO purpose, but users should review it because it depends on an unpinned external ClawLink plugin that handles account pairing and credentials.

Before installing, verify the ClawLink plugin's publisher, version, source, and permissions, and understand that it will broker DataForSEO access, store local device credentials, and may consume paid DataForSEO credits when tasks are run. Use explicit confirmation for large crawls, bulk queries, or any action that can affect account spending.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 31–35
Vulnerability Type: Unpinned external dependency
Risk Level: Medium

Vulnerable Code

markdown
**Step 1** — Install the ClawLink plugin:
text
openclaw plugins install clawhub:clawlink-plugin

Technical Analysis

The skill directs users to install the third-party clawlink-plugin package without specifying an immutable version, integrity hash, or verifiable signature. The plugin's implementation is not included in the audited project, so its behavior cannot be assessed from this package. The command consequently trusts whichever artifact the external registry resolves at installation time.

This creates a supply-chain risk: compromise of the package publisher, registry, release process, or package ownership could cause users to install code different from the version originally reviewed. The risk is heightened because the documentation indicates that the plugin participates in account pairing, stores device credentials in local OpenClaw configuration, and brokers access to DataForSEO.

Attack Path

  1. An attacker compromises the package publisher, registry account, distribution infrastructure, or another component controlling clawhub:clawlink-plugin.
  2. The attacker publishes a modified malicious release under the same mutable package identifier.
  3. A user follows the skill's installation command.
  4. OpenClaw resolves and installs the attacker-controlled release because no version or integrity constraint is supplied.
  5. The installed plugin executes within the OpenClaw plugin trust boundary.
  6. Depending on its granted permissions, the malicious plugin could inspect accessible configuration or credentials, alter proxied tool operations, or transmit integration data externally.

Impact Assessment

Successful exploitation could provide execution within the privileges granted to OpenClaw plugins. Potentially exposed assets include locally stored ClawLink de ...[truncated 417 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an immutable, security-reviewed version rather than installing the mutable package name alone.
  2. Publish and verify a cryptographic checksum or trusted signature for the exact plugin artifact.
  3. Document the authoritative publisher identity and verified source repository.
  4. Provide reproducible-build instructions or source provenance that maps the reviewed source to the distributed artifact.
  5. Review the plugin's manifest, requested permissions, credential handling, network destinations, update mechanism, and local storage protections before recommending installation.
  6. Apply least privilege so the plugin can access only the configuration and integration operations required for DataForSEO.
  7. Require explicit review and approval before upgrades, particularly when a new release changes permissions or credential-handling behavior.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The tool reference describes dataforseo_create_serp_google_events_task as "English only," which is a natural-language locale constraint. Because the documentation does not present this as a user-selectable option or explain a justified compliance-bound limitation for the skill as a whole, it constitutes a language/locale policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The surrounding comments say the example is for a Google organic SERP task and then 'Get results,' which implies retrieving the SERP task output. Instead, the code calls dataforseo_get_keywords_data_google_search_volume_task_by_id, a different keyword-volume endpoint unrelated to the created SERP task, so the documentation and code contradict each other.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.