Back to skill

Security audit

Gmail

Security checks for vulnerabilities and agentic risk

Overview

This Gmail skill is openly documented, but it asks users to trust a third-party hosted service and plugin with full Gmail mailbox access.

Install only if you are comfortable granting ClawLink and its plugin full access to your Gmail account, including reading mail, sending mail, modifying labels, and deleting messages. Prefer a separate or lower-risk Google account if testing, review Google's consent screen carefully, and revoke access from Google account permissions when you no longer need it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:42
Finding

Unverifiable Third-Party Plugin Receives Full Gmail Mailbox Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9-11, 42-46, 70-80, 91-97, 303-313
Vulnerability Type: Third-party dependency and hosted-service trust exposure
Risk Level: High

Vulnerable Code

markdown
This skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=gmail-email) for hosted connection flows and credentials so you do not need to configure Gmail API access yourself.
bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart
markdown
All Gmail tool calls are authenticated automatically by ClawLink using the user's connected Google account.

**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Gmail API request on the user's behalf.
markdown
- The connection is an OAuth grant approved on Google's own consent screen. It covers full mailbox access (Google's `https://www.googleapis.com/auth/mail.google.com` scope), which is what read, search, draft, send, forward, and label operations require.

Technical Analysis

The Skill directs the user to install and explicitly allowlist an external plugin, restart the OpenClaw gateway, and delegate Gmail OAuth token custody and API request processing to the hosted ClawLink service. The audited project contains only SKILL.md; it does not include the plugin implementation, an immutable dependency digest, or other material that would allow the plugin's token handling, network behavior, or confirmation enforcement to be independently verified.

The granted https://www.googleapis.com/auth/mail.google.com scope provides complete mailbox access. This scope is consistent with the Skill's entire advertised feature set, including reading, sending, modifying, and deleting messages. However, it exceeds least privilege for users who only requ ...[truncated 2377 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specific, immutable version and verified cryptographic digest rather than installing an unqualified package reference.
  2. Publish or include the auditable plugin source, dependency lockfiles, build provenance, signatures, and reproducible-build instructions.
  3. Verify package signatures and provenance before installation, and fail closed when verification is unavailable.
  4. Do not automatically allowlist the plugin. Present the permissions and external trust boundary to the user and require explicit approval before changing tools.alsoAllow.
  5. Offer direct Gmail API integration where feasible so credentials and mailbox content do not need to transit an additional hosted intermediary.
  6. Split functionality into narrower OAuth grants. Use read-only, compose, send, modify, or settings scopes according to the features the user actually enables instead of requesting full mailbox access by default.
  7. Enforce previews and user confirmations in a trusted local layer before any send, forward, modification, trash, or permanent-delete request reaches the plugin.
  8. Apply stronger, separate confirmation for bulk modification and permanent deletion. Display recipients, subject, body, affected message count, and irreversible consequences.
  9. Document exactly which data is transmitted to ClawLink, where it is processed, retention periods, logging practices, encryption controls, administrator access, incident response, and deletion procedures.
  10. Store OAuth tokens using a dedicated secrets-management system with encryption at rest, strict service isolation, access auditing, short-lived credentials where supported, and prompt revocation on disconnect.
  11. Provide users with clear instructions for reviewing and revoking access through Google account permissions, and verify that server-side token copies are invalidated and deleted after revocation.
  12. Subject plugin updates and the hosted service to inde ...[truncated 108 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.