Back to skill

Security audit

Dynamics 365

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Dynamics 365 CRM connector guide that uses ClawLink, with expected access to CRM records and clearly described setup steps.

Install only if you trust ClawLink and the OpenClaw package source. Use a least-privileged Dynamics 365 account, review CRM writes before confirming them, and remember that leads, invoices, opportunities, and sales orders may contain sensitive business data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:29-33
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code:

text
**Step 1** — Install the ClawLink plugin:
text
openclaw plugins install clawhub:clawlink-plugin
text
Start a fresh chat after installing.

Technical Analysis

The documented installation command does not specify a fixed version or immutable integrity digest for clawhub:clawlink-plugin. Consequently, the plugin installed by a user can differ from the version that existed when this Skill was reviewed. Starting a fresh chat then loads the installed plugin and exposes its tools to the agent environment.

This creates a supply-chain trust gap: compromise of the package registry entry, publisher account, distribution infrastructure, or a future plugin release could cause users to install executable logic that was not covered by this audit. The reviewed file does not establish that the current plugin is malicious; the vulnerability is the use of a mutable, unverified dependency.

Attack Path

  1. An attacker compromises the plugin publisher account, registry entry, or release infrastructure, or otherwise causes a malicious future release to be distributed under clawhub:clawlink-plugin.
  2. A user follows the Skill instructions and runs the unpinned installation command.
  3. The package manager retrieves the attacker-controlled version because no reviewed version or digest is specified.
  4. The user starts a fresh chat as instructed, causing the plugin and its tools to be loaded.
  5. The compromised plugin executes within the permissions available to the OpenClaw plugin environment.
  6. Depending on granted access, it could misuse local plugin configuration, ClawLink device credentials, integration requests, or Dynamics 365 operations.

Impact Assessment

Successful exploitation could provide access to the privilege ...[truncated 511 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specifically reviewed version instead of installing a mutable latest release.
  2. Where supported, pin an immutable cryptographic digest in addition to the version.
  3. Document the verified publisher identity and authoritative package source.
  4. Require signature and checksum verification before installation.
  5. Audit the exact pinned plugin package together with this Skill, including its installation hooks, network destinations, credential handling, and local permissions.
  6. Apply least privilege to the plugin and connected Dynamics 365 account, limiting CRM roles to operations required by the user.
  7. Establish a controlled update process in which new plugin releases are reviewed and approved before the pinned version is changed.
  8. Provide revocation and incident-response guidance for ClawLink device credentials and Dynamics 365 OAuth authorization if dependency compromise is suspected.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.