Back to skill

Security audit

Notion

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently sets up a Notion integration through ClawLink, with notable but disclosed risks from installing and enabling an external OAuth-backed plugin.

Install only if you trust ClawLink and are comfortable granting it Notion OAuth access. Review the Notion permissions during authorization, share only the pages or databases needed, and expect the plugin to remain enabled for future OpenClaw chats until you remove or disable it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Unpinned Privileged Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 42–47; related credential-handling statement at lines 67–69
Vulnerability Type: Unpinned third-party dependency with access to OAuth-backed Notion operations
Risk Level: Medium

Vulnerable Code

markdown
Install the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.

```bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart
text

Related credential-handling behavior:

```markdown
**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Notion API request on the user's behalf.

Technical Analysis

The skill directs the agent to install clawhub:clawlink-plugin without specifying an immutable version, cryptographic digest, or other integrity constraint. It then adds the plugin to the tool allowlist and restarts the OpenClaw gateway.

The plugin is trusted to participate in authenticated Notion operations and, according to the documentation, ClawLink stores and injects the user's OAuth token. However, the plugin implementation is not included in the audited project, which contains only SKILL.md. Its implementation, credential controls, and network behavior therefore cannot be independently verified by this audit.

Installing a mutable package identifier creates a supply-chain risk: the package resolved during installation may differ from the version originally reviewed. If the package publisher, distribution account, registry, or release pipeline were compromised, a malicious release could execute with the plugin's granted capabilities after being explicitly allowlisted.

No evidence in the audited file proves that the current ClawLink plugin is malicious. The finding concerns the unsafe, unpinned insta ...[truncated 1739 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specific, reviewed version rather than installing a mutable package identifier.
  2. Verify the package with a publisher signature, cryptographic checksum, or equivalent integrity mechanism before installation.
  3. Record the expected package source, version, digest, publisher identity, and verification procedure in the skill documentation.
  4. Require explicit user approval before installation, allowlist modification, gateway restart, account pairing, and any expansion of OAuth scopes.
  5. Apply least privilege to the Notion integration by requesting only the scopes required for the requested operation and sharing only necessary workspace resources.
  6. Document ClawLink's token storage, encryption, retention, revocation, logging, and request-proxy behavior so users can make an informed authorization decision.
  7. Isolate the plugin with restricted filesystem, process, and outbound-network permissions where the OpenClaw runtime supports sandboxing.
  8. Revalidate the plugin version and integrity before gateway restarts or upgrades, and provide a documented rollback and token-revocation process.
  9. Prefer independently auditable or bundled integration code when practical, while continuing to avoid embedding OAuth secrets directly in the skill.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.