Back to skill

Security audit

HubSpot

Security checks for vulnerabilities and agentic risk

Overview

This HubSpot skill is a disclosed CRM integration, but users should only install it if they trust ClawLink and are comfortable granting HubSpot write access.

Before installing, verify that you trust ClawLink and the ClawHub plugin source, review the HubSpot OAuth permissions being granted, and keep write/delete operations behind explicit confirmation as the skill instructs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Privileged External Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–49; repeated at lines 455–456
Vulnerability Type: Unpinned third-party dependency with privileged tool access
Risk Level: Medium

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The equivalent configuration and restart commands are repeated in the troubleshooting instructions:

bash
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The skill instructs users to install clawlink-plugin from an external package registry without specifying an immutable version, content digest, or signature-verification procedure. It then adds the plugin to the tool allowlist and restarts the OpenClaw gateway, causing the externally supplied implementation to become active.

The audited project contains only SKILL.md; it does not include the plugin source, lock metadata, checksums, or reproducible build information. Consequently, the behavior of the installed component—including its treatment of OAuth tokens, proxied HubSpot requests, and CRM data—cannot be statically verified from this package.

This creates a supply-chain exposure: the artifact installed in the future may differ from the artifact that was reviewed. Exploitation would require compromise, replacement, or malicious publication of the referenced plugin package or its distribution infrastructure.

Attack Path

  1. An attacker compromises the plugin publisher account, package registry, build pipeline, or distribution artifact.
  2. The attacker publishes a modified release under the referenced unversioned package name.
  3. A user follows the skill instructions and installs the current package using: openclaw plugins install clawhub:clawlink-plugin.
  4. The user explicitly enables the plugin through tools.alsoAllow.
  5. The gateway restarts and loads the ...[truncated 1019 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an immutable, reviewed version and preferably a cryptographic content digest.
  2. Document and enforce package-signature or checksum verification before installation.
  3. Provide a verifiable source repository, release provenance, and reproducible build information for the plugin.
  4. Maintain a dependency lock or equivalent integrity metadata in the skill package.
  5. Require explicit user approval before plugin installation, allowlist modification, and gateway restart.
  6. Apply least privilege to the plugin and connected HubSpot account, limiting OAuth scopes to the features actually required.
  7. Separate read-only and write-capable permissions where supported.
  8. Record and monitor plugin installation, upgrades, OAuth access, and CRM write operations.
  9. Review new plugin releases before updating rather than automatically resolving an unversioned package to the latest artifact.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.