Back to skill

Security audit

Google Meet

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Google Meet integration, but installing it means trusting a third-party ClawLink plugin with access to Meet data.

Install only if you trust ClawLink and the ClawHub plugin source. During setup, review the Google OAuth consent screen, confirm any create/update/end-meeting action before it runs, and know how to revoke the Google connection or remove the plugin if you no longer want it enabled.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:43
Finding

Unpinned Third-Party Plugin Installation and Global Enablement

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43–50
Vulnerability Type: Unpinned third-party dependency installation and enablement
Risk Level: Medium

Vulnerable Code

markdown
## Install

Install the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.

```bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart
text

Equivalent enablement and restart commands are repeated in the troubleshooting procedure at `SKILL.md`, lines 273–280.

### Technical Analysis

The skill instructs the agent to install `clawlink-plugin` without specifying an immutable version, cryptographic digest, or signature-verification procedure. It then adds the plugin to `tools.alsoAllow` and restarts the OpenClaw gateway so the newly installed component becomes active.

Consequently, the code ultimately executed depends on whichever plugin release the external package source serves at installation time. Its behavior may change after this skill has been reviewed. The audited project contains only `SKILL.md`; it does not include the plugin implementation, so the plugin's network activity, credential handling, permission boundaries, and enforcement of user confirmation cannot be verified from the artifact.

The documentation also states that ClawLink stores OAuth tokens, proxies Google Meet requests, and can process participant information, recordings, and transcripts. These activities match the declared integration purpose, but they increase the sensitivity of a supply-chain compromise.

### Attack Path

1. An attacker compromises the plugin publisher account, distribution service, release process, or another dependency used by a later plugin release.
2. A user or agent follows the skill's unpinned installation command.
3. The external source supplies the compromised releas
...[truncated 1021 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin clawlink-plugin to a reviewed, immutable version rather than installing the latest package implicitly.
  2. Verify a publisher signature or documented cryptographic digest before enabling the plugin.
  3. Include the relevant plugin source and permission manifest in the review scope, or provide a reproducible-build reference to the exact audited release.
  4. Require explicit user approval before each security-sensitive setup step: installation, allowlisting, account pairing, and gateway restart.
  5. Restrict the plugin to only the Google Meet tools and OAuth scopes required for the requested operation.
  6. Document the OAuth scopes, token encryption and retention controls, revocation procedure, data-processing boundaries, and incident-response process.
  7. Isolate third-party plugins from unrelated host resources and credentials.
  8. Avoid automatically repeating installation or allowlisting commands during troubleshooting without first verifying the installed package's version, integrity, and publisher.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.