Back to skill

Security audit

MailerLite

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently connects OpenClaw to MailerLite through ClawLink and its sensitive account actions are disclosed with confirmation requirements.

Install only if you trust ClawLink and are comfortable granting it access to your MailerLite account. Review the connected account permissions, confirm every write or destructive action carefully, and revoke the MailerLite connection if you stop using the skill.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:46
Finding

Unpinned Third-Party Plugin Receives Credential-Bearing MailerLite Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12, 32, 46–48, and 70
Vulnerability Type: Unpinned third-party dependency with access to hosted OAuth credentials and proxied API operations
Risk Level: Medium

Complete Code Snippet

markdown
This skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=mailerlite-email-marketing) for hosted connection flows and credentials so you do not need to configure MailerLite API access yourself.
text
│                   │  5. Proxy Requests    │
bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart
markdown
**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every MailerLite API request on the user's behalf.

Technical Analysis

The installation procedure retrieves clawhub:clawlink-plugin without specifying an immutable version, package digest, checksum, or signature-verification step. It then adds the plugin to the allowed tool configuration and restarts the OpenClaw gateway, causing the downloaded component to become active.

This dependency occupies a sensitive trust position: the documented architecture states that ClawLink stores the user's MailerLite OAuth token and proxies API requests. The plugin can expose interfaces for reading subscriber and customer information and initiating campaigns, webhooks, batch requests, and destructive account operations. Although the Skill explicitly discloses this intermediary and requires confirmation for write operations, the repository contains no plugin implementation that can be audited and no mechanism that ensures a future installation resolves to the same reviewed artifact.

The issue is therefore a supply-chain integrity weakness rather than evidence that the current plugin is malicio ...[truncated 1925 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a reviewed, immutable version rather than installing a floating package identifier.
  2. Require an artifact digest or cryptographic checksum and verify it before installation.
  3. Require publisher signatures and fail closed when signature verification cannot be completed.
  4. Publish or link to the exact plugin source revision corresponding to the pinned artifact so its behavior can be independently audited.
  5. Document the permissions requested by the plugin and grant only the minimum MailerLite OAuth scopes needed for the requested operation.
  6. Separate read-only and write-capable authorization where MailerLite supports it.
  7. Enforce write confirmations in a trusted host or server-side policy layer rather than relying exclusively on plugin-provided behavior.
  8. Restrict access to high-impact operations such as campaign sending, subscriber deletion, GDPR erasure, webhook creation, and batch requests.
  9. Provide users with procedures to inspect active authorization, revoke the MailerLite token, disconnect ClawLink, and remove the plugin.
  10. Record package version, digest, installation time, authorization changes, and API operations in tamper-resistant audit logs.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.