Back to skill

Security audit

Facebook

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for managing Facebook Pages, but it asks users to install and allowlist an unpinned third-party plugin that can handle OAuth-backed page actions.

Review the ClawLink plugin and publisher before installing. Only connect Facebook Pages you are comfortable managing through ClawLink, and confirm every post, message, update, or delete preview carefully because those actions affect real public or user-facing Facebook resources.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Privileged Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47-49
Vulnerability Type: Supply-chain risk caused by an unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The allowlisting and restart instructions are also repeated at SKILL.md:275-276:

bash
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The installation command references clawhub:clawlink-plugin without specifying an immutable version, integrity digest, or signature-verification requirement. It then adds the installed plugin to the permitted tool list and restarts the gateway, causing the downloaded component to be loaded with integration access.

Because the dependency is mutable, the installed implementation may differ from the version that was previously reviewed. If the registry entry, publisher account, release pipeline, or package-distribution infrastructure is compromised, a malicious release could be delivered through the documented installation workflow. The audit found no evidence that the current plugin is malicious; the vulnerability is the absence of controls ensuring that users receive a specific audited artifact.

Attack Path

  1. An attacker compromises the plugin publisher account, package registry entry, or associated release pipeline.
  2. The attacker publishes a malicious build under the existing clawlink-plugin package name.
  3. A user follows the skill instructions and installs the package without an immutable version or integrity check.
  4. The instructions explicitly allowlist the plugin through tools.alsoAllow.
  5. The gateway restart loads the attacker-controlled plugin.
  6. The malicious plugin can abuse the integration context or expose deceptive too ...[truncated 839 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specific, audited version rather than installing a mutable package reference.
  2. Require verification against a publisher signature and a documented cryptographic digest before installation.
  3. Publish the authoritative package identity, source repository, release provenance, and expected signing key.
  4. Use reproducible builds or signed provenance attestations so users can verify that registry artifacts match reviewed source code.
  5. Separate installation, allowlisting, and gateway restart into distinct steps requiring explicit user approval.
  6. Apply least privilege to the plugin's tool and network access, and restrict it to only the Facebook capabilities required by the user.
  7. Review and pin upgrades before deployment instead of automatically accepting mutable releases.
  8. Document an incident-response procedure for revoking plugin access and connected OAuth credentials if package compromise is detected.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 263)May include surrounding context.

md
| Missing connection | Facebook is not connected. Direct the user to https://claw-link.dev/dashboard?add=facebook. |
| `(#404) Page not found` | The Page ID does not exist or is not accessible. |
| `(#200) Permission denied` | The app does not have the required permission. |
| `(#190) Token expired` | The access token has expired. Reconnect Facebook. |
| Write rejected | User did not confirm a write action. Always confirm before executing writes. |

### Troubleshooting: Tools Not Visible

Static analysis

No suspicious patterns detected.