Back to skill

Security audit

Google Tasks

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently connects OpenClaw to Google Tasks through ClawLink, with expected OAuth and task-management permissions, but users should understand the third-party plugin and hosted credential custody involved.

Install only if you are comfortable using ClawLink as a hosted intermediary for Google Tasks. Review the Google OAuth consent screen, grant only the Tasks access you intend, and confirm write or delete operations carefully before allowing the agent to run them.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Is Installed and Granted Tool Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:47-49 and SKILL.md:268-269
Vulnerability Type: Unpinned privileged third-party dependency
Risk Level: High

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The configuration and restart instructions are repeated in the troubleshooting workflow:

bash
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The Skill directs users to install clawhub:clawlink-plugin without specifying an immutable version, package digest, signature, or verified source revision. It then adds the plugin to the OpenClaw tool allowlist and restarts the gateway, causing the downloaded component to become active.

Because the effective plugin implementation is not present in the audited project, its behavior cannot be verified from SKILL.md. An unpinned registry dependency can change after this Skill has been reviewed. If the registry account, distribution infrastructure, or package itself is compromised, later installations could receive attacker-controlled code while retaining the same trusted package name.

The explicit allowlisting operation increases the consequence of dependency compromise because the installed plugin is authorized to expose and invoke tools in subsequent OpenClaw sessions.

Attack Path

  1. An attacker compromises the plugin publisher account, package registry, or distribution path for clawhub:clawlink-plugin.
  2. The attacker publishes a modified plugin under the same unversioned package identifier.
  3. A user follows the instructions in SKILL.md and installs the latest package associated with that identifier.
  4. The user adds the plugin to tools.alsoAllow.
  5. The gateway is restarted and loads the attacker-controlled plugin.
  6. The malic ...[truncated 762 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a reviewed, immutable version rather than installing an unrestricted current release.
  2. Verify the package using a cryptographic digest and publisher signature before installation.
  3. Publish or link to the exact source revision corresponding to the pinned artifact so its behavior can be independently audited.
  4. Use a trusted registry with package provenance, transparency logs, and protected publisher credentials.
  5. Restrict the plugin allowlist and runtime permissions to only the Google Tasks operations required by the Skill.
  6. Require explicit user approval before installing the plugin, changing the allowlist, or restarting the gateway.
  7. Run the plugin in a sandbox with limited filesystem, network, process, and credential access.
  8. Define a controlled update process in which each new plugin release is reviewed before the pinned version is changed.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:68
Finding

Third-Party Service Retains OAuth Authority and Proxies Google Tasks Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9-11, SKILL.md:68-76
Vulnerability Type: Expanded third-party authorization and data-access boundary
Risk Level: Medium

Relevant Code

markdown
Access Google Tasks via the Tasks API with managed OAuth authentication. Manage task lists, tasks, due dates, notes, and completion state.

This skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=google-tasks-tasks) for hosted connection flows and credentials so you do not need to configure Google Tasks API access yourself.
markdown
All Google Tasks tool calls are authenticated automatically by ClawLink using the user's connected Google account.

**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Google Tasks API request on the user's behalf.

### Getting Connected

1. Install the ClawLink plugin (see Install above).
2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.
3. Open https://claw-link.dev/dashboard?add=google-tasks and connect Google Tasks.
4. Call `clawlink_list_integrations` to verify the connection is active.

Technical Analysis

The integration architecture delegates OAuth credential custody and request proxying to ClawLink. The service therefore occupies a privileged position between OpenClaw and Google Tasks: it stores the user's OAuth token, injects that token into API requests, and processes task data returned through the integration.

This behavior is disclosed in the Skill and is consistent with its stated hosted-integration design; the reviewed file does not demonstrate covert credential theft or unauthorized exfiltration. Nevertheless, it expands the authorization boundary beyond the local agent and Google. The project does not include independently auditable implementation details establishing token encryption, retention limits, tenant isolatio ...[truncated 1487 chars]

Remediation
View remediation

Remediation Suggestions

  1. Display the exact requested Google OAuth scopes before the user authorizes the connection.
  2. Request only the minimum Google Tasks scopes necessary for the user's requested operations.
  3. Separate read-only and write-capable authorization so users who only need task retrieval do not grant modification authority.
  4. Document token encryption, retention, rotation, administrative-access controls, tenant isolation, incident response, and deletion practices.
  5. Provide clear instructions for revoking Google authorization and deleting tokens retained by ClawLink.
  6. Use short-lived access tokens and securely protected refresh tokens, with revocation on disconnect.
  7. Offer direct OAuth or locally managed credentials where practical so users can avoid delegating token custody to an intermediary.
  8. Obtain explicit informed consent before transmitting task content through the third-party service.
  9. Maintain auditable logs and user-visible connection activity without recording OAuth tokens or sensitive task content.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.