Back to skill

Security audit

Google Docs

Security checks for vulnerabilities and agentic risk

Overview

This Google Docs skill is coherent and disclosed, but it relies on an external ClawLink plugin and OAuth-backed access to read and modify documents.

Install only if you are comfortable using ClawLink as the managed OAuth bridge for Google Docs. Review the plugin source or verification page where available, use the least-privileged Google account suitable for the task, confirm all writes carefully, and revoke the Google authorization or remove the plugin allowlist entry when no longer needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Installation and Allowlisting

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–49
Vulnerability Type: Unpinned external dependency installed from a mutable package registry
Risk Level: Medium

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The same allowlisting and restart instructions are repeated at SKILL.md, lines 318–319:

bash
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The skill instructs users to install clawhub:clawlink-plugin without specifying an immutable version, digest, or integrity hash. It then adds the plugin to OpenClaw's tool allowlist and restarts the gateway, causing the newly installed component to become active.

The plugin implementation is not included in the audited project, which contains only SKILL.md. Consequently, the plugin's behavior, dependency tree, requested privileges, and handling of OAuth-backed Google Docs data cannot be verified from this artifact. The skill describes the package as “verified,” but no signature, checksum, immutable source reference, or other verification evidence is present in the repository.

This is a supply-chain trust weakness rather than evidence that the current package is malicious. Exploitation requires compromise or malicious replacement of the external package or its distribution channel.

Attack Path

  1. An attacker compromises the external package publisher, registry entry, release process, or a dependency used by clawlink-plugin.
  2. The mutable package identifier resolves to an attacker-controlled or compromised release.
  3. A user follows the documented command and installs that release without version or integrity verification.
  4. The user adds the plugin to tools.alsoAllow.
  5. The gateway restart activates the compromised plugin.
  6. The plugin may receive legitimate tool calls and interact ...[truncated 1012 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an immutable, reviewed version rather than installing a floating package identifier.
  2. Require verification using a cryptographic digest or trusted package signature before installation.
  3. Publish or vendor the corresponding plugin source and lockfile so its behavior and transitive dependencies can be audited.
  4. Record the expected publisher identity, package version, checksum, and verification procedure directly in the installation instructions.
  5. Use reproducible builds and a trusted release pipeline with protected signing keys and multi-party release approval.
  6. Apply least privilege to the plugin allowlist and grant only the Google OAuth scopes necessary for the requested operation.
  7. Separate read and write capabilities where supported, keeping write tools disabled until explicitly needed.
  8. Review plugin updates before deployment instead of automatically accepting mutable upstream releases.
  9. Revoke the integration's OAuth authorization and remove the plugin from the allowlist if package integrity cannot be established.
  10. Document how administrators can inspect the installed version and verify its integrity before restarting the gateway.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill is described as a Google Docs API integration for reading and modifying Docs documents, but the documentation explicitly says it can search and update documents stored in Google Drive. Several listed tools, such as document search and copy, rely on Drive-level file operations rather than purely document-content operations, which broadens the behavior beyond the stated Google Docs focus.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Including googledocs_list_spreadsheet_charts in a Google Docs skill expands capability into Google Sheets data discovery, which is outside the stated document scope and may expose linked spreadsheet metadata or contents unexpectedly. Even if access is limited by OAuth and integration permissions, this broadens the attack surface and can mislead users about what data the skill can inspect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.