Back to skill

Security audit

GitHub

Security checks for vulnerabilities and agentic risk

Overview

This skill openly sets up a GitHub integration through ClawLink and tells the agent to confirm write or destructive actions before running them.

Before installing, verify you trust the ClawLink plugin and only grant the GitHub repository permissions you need. Review any preview carefully before approving write, delete, workflow, or deployment actions, and revoke the GitHub connection or remove the plugin if you stop using it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:49
Finding

Unpinned Privileged Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 49–53
Vulnerability Type: Unpinned third-party dependency with immediate privileged activation
Risk Level: Medium

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The documented installation procedure retrieves clawlink-plugin from ClawHub without specifying an immutable version, commit, or cryptographic digest. The downloaded plugin is then added to OpenClaw's allowed tools and activated by restarting the gateway.

Because the package reference is mutable, the code installed by this command can differ from the version originally reviewed. The project provides no checksum, signature-verification procedure, or local plugin source through which the installed implementation can be independently validated. This creates a supply-chain trust boundary in which the security of the integration depends on the registry, publisher account, distribution infrastructure, and latest published plugin release.

The plugin has a sensitive role because it mediates GitHub operations authenticated through a connected OAuth account. Exploitation therefore requires a malicious or compromised plugin release and a user following the documented installation and connection procedure; the Skill file itself does not contain an embedded malicious payload.

Attack Path

  1. An attacker compromises the plugin publisher account, ClawHub distribution path, or another component capable of replacing the mutable clawlink-plugin package.
  2. The attacker publishes a modified release under the same unversioned package identifier.
  3. A user follows the instructions in SKILL.md and installs the package without an immutable version or digest.
  4. The configuration command explicitly adds the plugin to OpenClaw's allowed tools.
  5. Restarting the gateway loads an ...[truncated 1094 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a reviewed, immutable version rather than installing a mutable package reference.
  2. Where supported, pin and verify a cryptographic digest in addition to the version.
  3. Publish the expected package publisher identity, version, checksum, and signature-verification procedure in SKILL.md.
  4. Verify package provenance and integrity before adding the plugin to tools.alsoAllow.
  5. Separate installation from activation: do not allowlist the plugin or restart the gateway until integrity and provenance checks have succeeded.
  6. Use the minimum GitHub OAuth scopes required for the requested tasks and avoid broad repository or administrative permissions by default.
  7. Prefer read-only scopes unless the user explicitly enables write functionality.
  8. Document plugin update controls so later releases require review and explicit approval rather than being adopted implicitly through an unversioned installation.
  9. Revoke the GitHub connection and remove the plugin immediately if package integrity or publisher ownership cannot be verified.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.