Back to skill

Security audit

Kit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Kit email-marketing integration, but users should understand that it installs and trusts the external ClawLink plugin for authenticated account access.

Install only if you are comfortable granting ClawLink access to your Kit account through OAuth. Review the ClawLink plugin and service trust boundary, confirm writes carefully, and revoke the Kit connection if you no longer need the integration.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:46
Finding

Unpinned Privileged Third-Party Plugin Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 46–48
Vulnerability Type: Unpinned third-party dependency with privileged tool access
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The privileged configuration and restart commands are also repeated at lines 314–315:

bash
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The Skill instructs the user to install clawhub:clawlink-plugin without specifying an immutable version, cryptographic digest, or verified signature. It then explicitly adds that plugin to the OpenClaw tool allowlist and restarts the gateway so the component becomes active.

The plugin implementation is not included in the audited project, which contains only SKILL.md; therefore, its behavior and security properties cannot be independently reviewed from this artifact. The documented architecture states that ClawLink proxies API requests, while line 70 states that it stores and injects the user's Kit OAuth token. Consequently, this mutable dependency operates across a sensitive authentication and data-access boundary.

Exploitation depends on compromise, replacement, or malicious publication of the externally distributed plugin. There is no evidence in the audited file that the current plugin is malicious.

Attack Path

  1. An attacker compromises the plugin publisher, distribution account, registry entry, or mutable plugin release.
  2. The attacker publishes a modified build under the same unversioned clawhub:clawlink-plugin identifier.
  3. A user follows the Skill instructions and installs the current mutable release.
  4. The user adds the plugin to tools.alsoAllow.
  5. Restarting the OpenClaw gateway loads the compromised component.
  6. The component can abuse its role in authenticated K ...[truncated 677 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specific, audited version rather than a mutable package identifier.
  2. Require a cryptographic digest or verified publisher signature and validate it before installation.
  3. Publish or vendor the plugin source and reproducible build instructions so its behavior can be independently audited.
  4. Grant only the minimum tools and permissions needed for Kit operations instead of broadly trusting the plugin.
  5. Isolate the plugin and restrict its filesystem, network, process, and credential access where the platform supports sandboxing.
  6. Document the external credential trust boundary, token storage protections, retention policy, revocation procedure, and incident-response process.
  7. Require explicit user approval before installation, allowlist modification, gateway restart, or credential connection.
  8. Monitor dependency updates and security advisories, and require security review before changing the pinned release.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 321)May include surrounding context.

md
## Resources

- [Kit API Documentation](https://api.kit.com/)
- [Kit Broadcasts Guide](https://kit.com/creators/broadcasts)
- [Kit Sequences Guide](https://kit.com/creators/sequences)
- ClawLink: https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=kit-email-marketing

Static analysis

No suspicious patterns detected.