T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Google Analytics skill is mostly coherent, but it enables a broad third-party ClawLink plugin with hosted OAuth credentials and write-capable analytics tools, so it needs careful review before installation.
Install only if you are comfortable trusting ClawLink with OAuth-backed access to the Google Analytics properties available to your Google account. Review the Google OAuth scopes and GA4 property permissions, avoid approving writes unless the preview exactly matches your intent, and know how to revoke the ClawLink Google connection if you stop using it.
SKILL.md:47Unpinned Third-Party Plugin Installation
SKILL.md:48Broad Plugin Allowlisting with Access to Hosted OAuth Credentials
The skill gives conflicting guidance about key event creation: earlier sections instruct the agent to confirm and execute key event creation, while the notes later say key events are read-only via API and must be created in the Google Analytics UI. Contradictory execution guidance is dangerous because an agent may either attempt unsupported write behavior, or worse, mis-handle a different write-capable tool under the mistaken belief that it safely covers key events.
The manifest frames the skill as mainly reporting and limited management, but the documented tool catalog exposes additional write capabilities such as creating audience lists, custom dimensions/metrics, updating properties, and creating roll-up properties. This mismatch can cause users or downstream agents to invoke the skill under a lower-risk assumption, increasing the chance of unintended state-changing operations in a sensitive analytics environment.
The invocation text is broad and generic, encouraging use for many analytics-related tasks without precise trigger boundaries. In an agent setting, this increases over-invocation risk: the model may select this skill for loosely related requests and gain access to more powerful connected tools, including write operations, than the user likely intended.
The markdown includes openclaw gateway restart, which affects system/tool availability and effectively interrupts the current chat flow, but the warning appears only afterward as operational guidance rather than as a clear pre-action caution. For markdown files, behaviors affecting system integrity or workflow should be disclosed up front so users understand the impact before proceeding.
No suspicious patterns detected.