Back to skill

Security audit

ElevenLabs

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent ElevenLabs integration, but it asks users to install and allowlist an unpinned third-party plugin that will handle authenticated ElevenLabs requests.

Review the ClawLink plugin source, publisher, permissions, and release provenance before installing. Use a pinned or verified plugin version if OpenClaw supports it, and be prepared to disable the plugin and rotate your ElevenLabs API key if you suspect compromise.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Is Installed and Granted Tool Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–49
Vulnerability Type: Unpinned executable dependency
Risk Level: Medium

Complete Code Snippet:

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The documented setup installs clawlink-plugin without pinning an immutable version, commit, digest, or verified signature. It then explicitly adds that plugin to the allowed tool configuration and restarts the gateway, activating the installed package.

The reviewed project contains only SKILL.md; it does not include the plugin implementation or integrity metadata. Consequently, the executable behavior receiving tool access cannot be verified from this artifact. A mutable dependency may change after this skill has been reviewed, creating a supply-chain risk if its distribution account, package, release pipeline, or future version is compromised.

The trust impact is increased by the credential-handling role described at SKILL.md, line 71:

text
ClawLink stores the API key securely and injects it into every ElevenLabs API request on the user's behalf.

This statement does not demonstrate credential misuse. It does, however, establish that the external component occupies a security-sensitive position involving ElevenLabs credentials and authenticated API requests.

Attack Path

  1. An attacker compromises the plugin publisher, package registry entry, release pipeline, or another distribution component.
  2. The attacker publishes a malicious release under the unversioned clawlink-plugin identifier.
  3. A user follows the installation instructions in SKILL.md.
  4. OpenClaw resolves and installs the attacker-controlled release because no immutable version or digest is specified.
  5. The configuration command allowlists the plugin.
  6. The gateway restart ...[truncated 792 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a reviewed, immutable version rather than installing a mutable package identifier.
  2. Where supported, verify the package with a cryptographic digest and a trusted publisher signature before installation.
  3. Provide links to the auditable plugin source, signed release artifacts, and reproducible build or provenance records.
  4. Separate installation from allowlisting so package identity and integrity can be verified before tool access is granted.
  5. Document the plugin's exact runtime permissions, network destinations, credential-storage design, and credential-access boundaries.
  6. Apply least privilege by granting only the tools and account scopes required for ElevenLabs operations.
  7. Establish dependency update controls, including review and integrity verification before adopting a new plugin release.
  8. Provide revocation and incident-response instructions for disabling the plugin and rotating ElevenLabs credentials if compromise is suspected.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.