T08 · Insecure Dependencies
- Location
SKILL.md:46- Finding
Unpinned Third-Party Plugin Is Installed and Granted Tool Access
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent for Lemlist outreach, but it asks users to install and allow an unpinned external plugin that handles OAuth-backed Lemlist access and can perform business-impacting writes.
Review the ClawLink plugin source, publisher, version, and update policy before installing. Connect only a Lemlist account with the minimum needed permissions, verify previews before any write operation, and be especially careful with campaigns, lead status changes, schedules, unsubscribe/suppression changes, and exports.
SKILL.md:46Unpinned Third-Party Plugin Is Installed and Granted Tool Access
The table entry describes lemlist_get_contact_messages as "Get all messages exchanged with a specific contact," which is a read-only retrieval operation by its own wording, but the Mode column marks it as Write. This is an active documentation contradiction that could mislead an agent's confirmation and safety workflow.
No suspicious patterns detected.