Back to skill

Security audit

Freshservice

Security checks for vulnerabilities and agentic risk

Overview

The skill is clearly for Freshservice, but it asks users to install and allowlist an unpinned third-party plugin that will handle Freshservice credentials and business data.

Review the ClawLink plugin source, publisher, version, and integrity guarantees before installing. Use a Freshservice account with the least privileges needed, expect ClawLink to broker credentials and API requests, and confirm every write or delete preview carefully.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:52
Finding

Unpinned Third-Party Plugin Is Installed and Granted Tool Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 52–56
Vulnerability Type: Unpinned external dependency installed from a mutable package source
Risk Level: High

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The installation procedure retrieves clawlink-plugin from an external package registry using a mutable package identifier. It does not specify an audited version, immutable digest, signature, or checksum. The plugin's implementation is not included in the audited project, so its behavior cannot be verified from the available source.

The subsequent command adds the plugin to the OpenClaw tool allowlist, and restarting the gateway activates the installed component. This creates a supply-chain trust boundary in which externally controlled code is installed and authorized to operate as a tool provider.

Although the skill states that ClawLink stores credentials securely and proxies Freshservice requests, those guarantees cannot be validated without the plugin and service implementation. The finding does not establish that the current plugin is malicious; it establishes that the documented installation process does not cryptographically bind installation to the version reviewed or expected.

Attack Path

  1. An attacker compromises the external package registry, publisher account, distribution channel, or a later release associated with clawhub:clawlink-plugin.
  2. The attacker publishes a modified plugin under the same mutable package identifier.
  3. A user follows the instructions in SKILL.md and installs the plugin without a version or integrity constraint.
  4. The user adds the plugin to tools.alsoAllow.
  5. The gateway restart loads and activates the attacker-controlled plugin.
  6. The plugin can then abuse the permissions and data exposed through its tool-provider role, inc ...[truncated 934 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specific, audited version rather than using an unqualified mutable package name.
  2. Require an immutable content digest or cryptographic checksum and verify it before installation.
  3. Require package-signature verification against a trusted publisher key.
  4. Publish or bundle the exact plugin source so its behavior can be independently reviewed.
  5. Maintain a lockfile or equivalent integrity manifest recording the approved version and digest.
  6. Restrict the plugin's tool and host permissions according to least privilege.
  7. Isolate the plugin in a sandbox that limits filesystem, network, process, credential, and configuration access.
  8. Document the precise data and credentials available to the plugin and the external ClawLink service.
  9. Avoid automatically activating newly retrieved code; require explicit verification before allowlisting and gateway restart.
  10. Establish a controlled update process that audits each new release before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 277)May include surrounding context.

md
## Resources

- [Freshservice API Documentation](https://api.freshservice.com/)
- [Freshservice Ticket API](https://api.freshservice.com/v2/tickets.html)
- [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=freshservice-it)
- [ClawLink Docs](https://docs.claw-link.dev/openclaw)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 278)May include surrounding context.

md
## Resources

- [Freshservice API Documentation](https://api.freshservice.com/)
- [Freshservice Ticket API](https://api.freshservice.com/v2/tickets.html)
- [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=freshservice-it)
- [ClawLink Docs](https://docs.claw-link.dev/openclaw)

Static analysis

No suspicious patterns detected.