Back to skill

Security audit

Google Slides

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Google Slides integration that uses ClawLink OAuth and requires confirmation before writes, with a supply-chain caution around installing the companion plugin.

Before installing, understand that this depends on the ClawLink plugin and hosted OAuth service. Use it only if you trust ClawLink with access to your Google Slides account, review Google’s requested permissions, and confirm every write or destructive change before execution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Installation and Broad Tool Authorization

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:47-49
Vulnerability Type: Unpinned third-party dependency installation and authorization
Risk Level: Medium

Vulnerable Code:

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The same authorization and restart commands are repeated at SKILL.md:311-312.

Technical Analysis

The installation command references clawhub:clawlink-plugin without an immutable version, digest, or checksum. The instructions then add that plugin to the tool allowlist and restart the gateway, causing the downloaded component to be loaded with authorized tool access.

Because the audited project does not contain the plugin implementation, a lockfile, a cryptographic digest, or verification steps tied to a specific artifact, reviewers cannot establish that the code installed later will be identical to the code originally assessed. A compromised publisher account, registry, or mutable package release could therefore introduce altered plugin code through the documented installation workflow.

The Skill also states that ClawLink stores the user's OAuth token and injects it into Google Slides requests (SKILL.md:71). This creates a sensitive external trust boundary and raises the potential impact if the authorized dependency is compromised. The audit found no evidence that the current plugin is malicious or that credentials are presently being misused; the finding concerns the unsafe dependency acquisition and authorization process.

Attack Path

  1. An attacker compromises the plugin publisher account, package registry, release process, or another part of the distribution chain.
  2. The attacker publishes modified code under the mutable clawhub:clawlink-plugin reference.
  3. A user follows the Skill instructions and installs that reference without verifying a version-speci ...[truncated 1159 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an audited, immutable version rather than installing a mutable package reference.
  2. Verify a publisher signature or cryptographic digest before installation and document the expected value in the setup procedure.
  3. Publish reproducible build information and artifact provenance so users can validate the installed component.
  4. Grant only the minimum integration-specific tools and permissions needed instead of broadly authorizing the entire plugin where finer controls are available.
  5. Require explicit user approval before plugin installation, allowlist modification, OAuth connection, and gateway restart.
  6. Enforce write confirmation independently of the third-party plugin so a compromised dependency cannot bypass confirmation controls.
  7. Document incident-response steps, including disabling and uninstalling the plugin, removing its allowlist entry, disconnecting ClawLink, revoking Google OAuth access, and reviewing account activity.
  8. Regularly re-audit pinned releases and monitor the package source for publisher, ownership, signing-key, or provenance changes.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.