Back to skill

Security audit

Intercom

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Intercom integration, but it asks users to install an unpinned external OAuth-backed plugin and exposes broad customer-data export capabilities without strong warnings or scope details.

Review this carefully before installing. Only connect an Intercom workspace if you trust ClawLink and the clawlink-plugin with OAuth-backed access to customer conversations, contacts, tickets, help-center content, transcripts, and exports. Prefer a least-privilege Intercom account, confirm any write/delete/export action explicitly, and verify how to revoke the OAuth connection and remove the plugin if needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:46
Finding

Unpinned External Plugin Receives OAuth-Backed Intercom Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 46-48
Vulnerability Type: Unpinned third-party plugin installation and supply-chain exposure
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Related trust and credential-flow statements appear at SKILL.md:32, SKILL.md:70, and SKILL.md:76:

text
5. Proxy Requests

No API key is required in chat. ClawLink stores the OAuth token securely
and injects it into every Intercom API request on the user's behalf.

Open https://claw-link.dev/dashboard?add=intercom and connect Intercom
(requires an active Intercom workspace).

Technical Analysis

The installation command references clawhub:clawlink-plugin without an immutable version, release digest, or other integrity constraint. The subsequent configuration explicitly permits the plugin as an OpenClaw tool and restarts the gateway so that the installed component becomes active.

This creates a supply-chain trust boundary that cannot be fully audited from the submitted project. The project contains only SKILL.md; the plugin implementation and hosted ClawLink service are external. Consequently, the behavior reviewed in this repository does not establish that the component installed in the future will be identical to the component intended by the documentation.

The exposure is significant because ClawLink is described as storing the user's OAuth token and injecting it into proxied Intercom requests. The documented tool catalog includes access to customer conversations, contacts, companies, tickets, call transcripts, data exports, help-center content, and destructive operations. Although the Skill requires confirmation for write operations, an altered external plugin or backend may not reliably enforce those instructions.

This finding does not ...[truncated 1867 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specific immutable release version rather than installing a mutable package name.
  2. Verify the downloaded artifact using a publisher signature and a documented cryptographic digest before installation.
  3. Configure installation to fail closed if the signature, version, or digest does not match the reviewed artifact.
  4. Publish or bundle the plugin source corresponding to the pinned release so its credential handling, network behavior, and confirmation enforcement can be independently audited.
  5. Document the exact Intercom OAuth scopes requested and remove all scopes not required for the user's selected operations.
  6. Separate read-only and write-capable authorization profiles where supported, with read-only access as the default.
  7. Require explicit, independently enforced authorization for destructive or externally visible actions rather than relying solely on natural-language Skill instructions.
  8. Document token retention, encryption, logging, subprocess access, administrator access, revocation, and incident-response practices for the hosted service.
  9. Provide clear instructions for revoking the Intercom connection, uninstalling the plugin, and removing it from tools.alsoAllow.
  10. Use signed releases, protected publisher accounts, reproducible builds, dependency locking, and automated supply-chain scanning throughout the plugin release process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents intercom_create_data_export and intercom_download_data_export for exporting workspace message content, but the surrounding guidance does not give a clear, prominent warning that these actions can extract large volumes of sensitive customer communications. In a customer-support context, exported Intercom data may include PII, support transcripts, attachments, and confidential business information, so treating export as an ordinary capability increases the risk of overbroad disclosure or accidental exfiltration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.