Back to skill

Security audit

Freshdesk

Security checks for vulnerabilities and agentic risk

Overview

This Freshdesk skill is coherent and disclosed, but it relies on a persistent ClawLink plugin that will handle connected Freshdesk access.

Install only if you are comfortable connecting Freshdesk through ClawLink and enabling its OpenClaw plugin. Use a Freshdesk account with the minimum permissions needed, review write previews carefully, and revoke the ClawLink connection if you no longer need it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:54
Finding

Unpinned Privileged Third-Party Integration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 54–62
Vulnerability Type: Unpinned third-party plugin with access to credentials and Freshdesk operations
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The associated credential delegation is documented at lines 77–79:

text
All Freshdesk tool calls are authenticated automatically by ClawLink using the user's connected Freshdesk account.

No API key is required in chat. ClawLink stores credentials securely and injects them into every Freshdesk API request on the user's behalf.

Technical Analysis

The installation command identifies clawlink-plugin without an immutable version, release digest, checksum, or signature requirement. The subsequent configuration command explicitly allows the plugin's tools, and the gateway restart loads the installed component.

The plugin implementation is not included in the audited project, so its behavior and security controls cannot be independently verified from this artifact. According to the skill documentation, ClawLink stores or mediates Freshdesk credentials and injects them into API requests. This creates a supply-chain trust boundary in which a mutable external dependency receives access to sensitive customer-support data and write-capable Freshdesk operations.

This is an insecure dependency risk rather than evidence that the current plugin is malicious. Exploitation requires the plugin distribution source, an upstream release, or the installation channel to be compromised or otherwise serve an unsafe version.

Attack Path

  1. An attacker compromises the plugin publisher, package registry entry, distribution channel, or a future unpinned plugin release.
  2. A user follows the documented installation command, which resolves the mutable `clawhub ...[truncated 1281 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specific immutable version and, where supported, a cryptographic content digest.
  2. Require package signature and checksum verification before installation.
  3. Publish the plugin source and reproducible build instructions so the installed artifact can be independently audited.
  4. Use a trusted registry namespace with publisher verification and release-provenance attestations.
  5. Restrict plugin permissions and Freshdesk API scopes to the minimum required for the requested operation.
  6. Separate read-only and write-capable authorization, granting write access only when necessary.
  7. Require explicit user approval before plugin installation, allowlisting, gateway restart, account pairing, and scope changes.
  8. Document credential storage, encryption, retention, revocation, logging, and incident-response controls for the hosted proxy.
  9. Provide rapid token revocation and plugin rollback mechanisms for compromised releases.
  10. Retain the documented preview and confirmation workflow for all write operations, while enforcing equivalent authorization controls in the plugin and server-side proxy rather than relying solely on skill instructions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.