Back to skill

Security audit

Google Ads

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for Google Ads work, but it asks users to install and allowlist an unpinned third-party ClawLink plugin that can mediate high-impact Google Ads actions.

Review this before installing if the Google Ads account has production spend or customer-list access. Install only if you trust ClawLink and the ClawHub package source, verify the plugin through the linked provider materials, connect only the Google Ads accounts needed, and require a clear preview plus explicit confirmation before any write action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:54
Finding

Unpinned Privileged Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 54–58
Vulnerability Type: Supply-chain risk from an unpinned third-party plugin
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The setup procedure installs clawlink-plugin from an external package source without specifying an immutable version, content digest, checksum, or verifiable signature. It then explicitly allowlists the plugin and restarts the OpenClaw gateway, causing externally supplied executable code to become active.

The repository contains only SKILL.md; it does not include the plugin source, a lock file, a cryptographic integrity manifest, or other evidence that would permit review of the installed artifact. Although the document calls the plugin “verified,” that assertion cannot be independently established from the audited project.

This creates a supply-chain risk because the effective plugin artifact may change after this skill has been reviewed. Compromise of the package publisher, registry, distribution channel, or mutable package release could result in users installing behavior different from the behavior represented by this document.

Attack Path

  1. An attacker compromises the plugin publisher account, package registry entry, distribution infrastructure, or another component of the plugin supply chain.
  2. The attacker replaces or updates the mutable clawlink-plugin artifact with a malicious release.
  3. A user follows the documented installation command, which retrieves the current external artifact without validating an immutable version or digest.
  4. The next command adds the plugin to tools.alsoAllow, granting it access through OpenClaw’s tool configuration.
  5. The gateway restart loads and activates the compromised plugin.
  6. The malicious ...[truncated 1069 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an immutable, reviewed version rather than installing a mutable package name.
  2. Require a cryptographic digest or checksum and verify it before installation.
  3. Require signed releases and validate the signature against a documented trusted publisher key.
  4. Publish or reference the exact plugin source corresponding to the pinned artifact so its behavior can be independently audited.
  5. Add a lock file or integrity manifest containing the expected version, digest, source repository, and build provenance.
  6. Review and document the plugin’s required permissions before adding it to tools.alsoAllow.
  7. Apply least privilege by exposing only the tools and integrations necessary for Google Ads operations.
  8. Isolate the plugin in a restricted runtime with limited filesystem, network, process, and credential access.
  9. Separate installation, allowlisting, and gateway activation into explicit steps so integrity and permission checks occur before activation.
  10. Establish a controlled update process in which each new plugin artifact is reviewed and its digest approved before deployment.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.