Back to skill

Security audit

Motion

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Motion integration that relies on ClawLink for authenticated access, with some normal but important trust and install considerations.

Before installing, confirm you trust ClawLink and the ClawHub plugin source because it will store or broker Motion credentials and can read or change Motion data available to your account. Use the documented confirmations carefully for creates, updates, deletes, unassignments, and custom-field changes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:41
Finding

Unpinned Third-Party Plugin Installed with Credential-Bearing Integration Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 41–47 and 70–79
Vulnerability Type: Unpinned third-party dependency with privileged integration access
Risk Level: Medium

Vulnerable Code

markdown
## Install

Install the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.

```bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart
text

The same file describes the plugin's credential-bearing role:

```markdown
## Authentication

All Motion tool calls are authenticated automatically by ClawLink using the user's connected Motion account.

**No API key is required in chat.** ClawLink stores the API key securely and injects it into every Motion API request on the user's behalf.

Technical Analysis

The skill instructs the agent to install clawhub:clawlink-plugin without specifying an immutable version, package digest, signature, or other integrity constraint. It then modifies the OpenClaw allowlist and restarts the gateway, activating the newly acquired component.

The project contains only SKILL.md; consequently, the plugin implementation that handles credentials and authenticated requests is outside the reviewed artifact. Although the documentation calls the plugin “verified,” it provides no locally verifiable checksum, signature, immutable release reference, or source snapshot. A mutable package release or compromised distribution account could therefore cause users to install code different from the code originally reviewed.

This risk is amplified because the plugin acts as an authenticated intermediary. According to the skill, ClawLink stores the Motion API key and injects it into Motion API requests. The documented tool catalog includes access to workspace, project, task, user, schedule, comment, and custom-field data, as well as ...[truncated 1683 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an immutable, audited version rather than installing a mutable package identifier.
  2. Require verification of a cryptographic digest or publisher signature before installation and activation.
  3. Publish or vendor the exact plugin source corresponding to the pinned release so its behavior can be audited alongside the skill.
  4. Separate installation, allowlisting, and gateway restart into distinct user-approved steps, showing the exact version and integrity metadata before activation.
  5. Document the exact Motion authorization scopes requested and apply least privilege, excluding destructive capabilities unless explicitly required.
  6. Isolate the plugin with restricted filesystem, network, process, and secret access appropriate to its function.
  7. Use short-lived credentials where supported, with secure storage, rotation, revocation, and audit logging.
  8. Enforce write and destructive-operation confirmation outside the plugin itself so a compromised dependency cannot bypass confirmation policy.
  9. Maintain an approved-version policy and monitor the dependency for publisher changes, revoked signatures, and unexpected release updates.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.