Back to skill

Security audit

Google Analytics

Security checks for vulnerabilities and agentic risk

Overview

This Google Analytics skill is mostly coherent, but it enables a broad third-party ClawLink plugin with hosted OAuth credentials and write-capable analytics tools, so it needs careful review before installation.

Install only if you are comfortable trusting ClawLink with OAuth-backed access to the Google Analytics properties available to your Google account. Review the Google OAuth scopes and GA4 property permissions, avoid approving writes unless the preview exactly matches your intent, and know how to revoke the ClawLink Google connection if you stop using it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Installation

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:48
Finding

Broad Plugin Allowlisting with Access to Hosted OAuth Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill gives conflicting guidance about key event creation: earlier sections instruct the agent to confirm and execute key event creation, while the notes later say key events are read-only via API and must be created in the Google Analytics UI. Contradictory execution guidance is dangerous because an agent may either attempt unsupported write behavior, or worse, mis-handle a different write-capable tool under the mistaken belief that it safely covers key events.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest frames the skill as mainly reporting and limited management, but the documented tool catalog exposes additional write capabilities such as creating audience lists, custom dimensions/metrics, updating properties, and creating roll-up properties. This mismatch can cause users or downstream agents to invoke the skill under a lower-risk assumption, increasing the chance of unintended state-changing operations in a sensitive analytics environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The invocation text is broad and generic, encouraging use for many analytics-related tasks without precise trigger boundaries. In an agent setting, this increases over-invocation risk: the model may select this skill for loosely related requests and gain access to more powerful connected tools, including write operations, than the user likely intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown includes openclaw gateway restart, which affects system/tool availability and effectively interrupts the current chat flow, but the warning appears only afterward as operational guidance rather than as a clear pre-action caution. For markdown files, behaviors affecting system integrity or workflow should be disclosed up front so users understand the impact before proceeding.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.