Back to skill

Security audit

Google Forms

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly sets up a Google Forms integration through ClawLink, with disclosed OAuth use and confirmation requirements for writes.

Before installing, understand that this connects your Google account through ClawLink and enables tools that can read form data and, with confirmation, modify forms or responses. Use it only if you trust the ClawLink plugin and hosted OAuth service, and review write previews carefully before approving changes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:51
Finding

Unpinned Privileged Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 51–55
Vulnerability Type: Unpinned third-party dependency with privileged OAuth and tool access
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The skill instructs the user or agent to install clawlink-plugin from a third-party package registry without specifying an immutable version, digest, or verified signature. It then explicitly allowlists the plugin and restarts the OpenClaw gateway, causing the installed component to become active.

Because the plugin brokers Google OAuth authentication and Google Forms operations, it occupies a privileged trust position. The reviewed skill provides no local plugin implementation to audit and no procedure for verifying the downloaded artifact against an expected cryptographic digest. Consequently, the code ultimately executed can differ over time from the component originally reviewed.

This is a supply-chain weakness rather than proof that the current plugin is malicious. Exploitation requires compromise or malicious control of the registry entry, publisher account, distribution infrastructure, or a later plugin release.

Attack Path

  1. An attacker compromises the plugin publisher account, registry entry, or distribution infrastructure, or publishes a malicious update under the same mutable package identifier.
  2. A user follows the skill instructions and runs the unpinned installation command.
  3. OpenClaw retrieves the attacker-controlled plugin version because no version or digest constrains the artifact.
  4. The configuration command allowlists the plugin's tools.
  5. Restarting the gateway loads and activates the compromised plugin.
  6. The user pairs the plugin and connects a Google account through the hosted OAuth flow.
  7. The compromised component abuses its delegate ...[truncated 1136 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a reviewed, immutable version rather than installing a mutable package identifier.
  2. Verify the downloaded artifact using a trusted cryptographic digest or registry-supported signature before activation.
  3. Document the expected publisher identity, signature chain, version, and checksum.
  4. Make plugin upgrades explicit and require a new security review and user approval before installing them.
  5. Publish or vendor the relevant plugin source and permission manifest so reviewers can inspect OAuth handling, network destinations, and tool behavior.
  6. Request only the minimum Google OAuth scopes needed for the selected operation.
  7. Apply least-privilege restrictions to the plugin's local capabilities, network access, and available OpenClaw tools.
  8. Enforce write confirmation independently at the trusted host boundary rather than relying solely on behavior implemented by the downloaded plugin.
  9. Provide token revocation, connection auditing, and rapid rollback procedures for compromised releases.
  10. Avoid activating the dependency automatically after installation until its integrity and requested permissions have been verified.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.