T08 · Insecure Dependencies
- Location
SKILL.md:42- Finding
Unverifiable Third-Party Plugin Receives Full Gmail Mailbox Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:9-11, 42-46, 70-80, 91-97, 303-313
Vulnerability Type: Third-party dependency and hosted-service trust exposure
Risk Level: HighVulnerable Code
markdown This skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=gmail-email) for hosted connection flows and credentials so you do not need to configure Gmail API access yourself.bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartmarkdown All Gmail tool calls are authenticated automatically by ClawLink using the user's connected Google account. **No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Gmail API request on the user's behalf.markdown - The connection is an OAuth grant approved on Google's own consent screen. It covers full mailbox access (Google's `https://www.googleapis.com/auth/mail.google.com` scope), which is what read, search, draft, send, forward, and label operations require.Technical Analysis
The Skill directs the user to install and explicitly allowlist an external plugin, restart the OpenClaw gateway, and delegate Gmail OAuth token custody and API request processing to the hosted ClawLink service. The audited project contains only
SKILL.md; it does not include the plugin implementation, an immutable dependency digest, or other material that would allow the plugin's token handling, network behavior, or confirmation enforcement to be independently verified.The granted
https://www.googleapis.com/auth/mail.google.comscope provides complete mailbox access. This scope is consistent with the Skill's entire advertised feature set, including reading, sending, modifying, and deleting messages. However, it exceeds least privilege for users who only requ ...[truncated 2377 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a specific, immutable version and verified cryptographic digest rather than installing an unqualified package reference.
- Publish or include the auditable plugin source, dependency lockfiles, build provenance, signatures, and reproducible-build instructions.
- Verify package signatures and provenance before installation, and fail closed when verification is unavailable.
- Do not automatically allowlist the plugin. Present the permissions and external trust boundary to the user and require explicit approval before changing
tools.alsoAllow. - Offer direct Gmail API integration where feasible so credentials and mailbox content do not need to transit an additional hosted intermediary.
- Split functionality into narrower OAuth grants. Use read-only, compose, send, modify, or settings scopes according to the features the user actually enables instead of requesting full mailbox access by default.
- Enforce previews and user confirmations in a trusted local layer before any send, forward, modification, trash, or permanent-delete request reaches the plugin.
- Apply stronger, separate confirmation for bulk modification and permanent deletion. Display recipients, subject, body, affected message count, and irreversible consequences.
- Document exactly which data is transmitted to ClawLink, where it is processed, retention periods, logging practices, encryption controls, administrator access, incident response, and deletion procedures.
- Store OAuth tokens using a dedicated secrets-management system with encryption at rest, strict service isolation, access auditing, short-lived credentials where supported, and prompt revocation on disconnect.
- Provide users with clear instructions for reviewing and revoking access through Google account permissions, and verify that server-side token copies are invalidated and deleted after revocation.
- Subject plugin updates and the hosted service to inde ...[truncated 108 chars]
