Back to skill

Security audit

OneNote Notes

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly designed to manage OneNote through ClawLink, but it asks users to install and allowlist an unpinned external plugin that handles Microsoft OAuth tokens and OneNote data.

Install only if you trust ClawLink and the ClawHub plugin distribution. Before connecting Microsoft, review the permissions shown in the OAuth consent screen, avoid granting broader access than needed, and revoke the Microsoft connection or remove the plugin if you stop using it. Confirm all write or delete actions carefully.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Handles OAuth Credentials and OneNote Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–49 and line 71
Vulnerability Type: Unpinned privileged third-party dependency
Risk Level: High

Complete Code Snippet

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The plugin is subsequently entrusted with OAuth credentials:

text
**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Microsoft Graph request on the user's behalf.

Technical Analysis

The skill instructs users to install clawlink-plugin without specifying an immutable version, cryptographic digest, or verifiable publisher signature. It then explicitly allowlists the plugin and restarts the gateway so that the new component is loaded.

This dependency occupies a sensitive trust position: according to the skill documentation, ClawLink stores Microsoft OAuth tokens, injects them into Microsoft Graph requests, and proxies requests involving private OneNote content. The audited project contains only SKILL.md; it does not include the plugin source or a lockfile, signature, checksum, or reproducible build reference. Consequently, the audit cannot verify the plugin's credential storage, network behavior, update process, effective permissions, or correspondence to reviewed source code.

The finding is a supply-chain exposure rather than confirmed malicious behavior. The documentation openly identifies ClawLink as an OAuth intermediary, and no direct evidence of credential theft, malware, or hidden exfiltration was found in the artifact.

Attack Path

  1. An attacker compromises, replaces, or publishes a malicious update to the unpinned clawlink-plugin distribution.
  2. A user follows the skill instructions and installs whichever package version the registry currently resolves.
  3. The user adds the plugin to tools.alsoAllow and restarts the gateway, ...[truncated 1147 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an immutable, reviewed version rather than installing an unconstrained package reference.
  2. Verify the dependency using a trusted publisher signature and a documented cryptographic digest.
  3. Publish or reference the exact source revision and reproducible build materials corresponding to the distributed plugin.
  4. Add a lockfile or equivalent dependency manifest that prevents silent version substitution.
  5. Document all Microsoft OAuth scopes and justify each scope according to least privilege.
  6. Separate read-only and write-capable authorization where supported, requesting write access only when necessary.
  7. Document token encryption, retention, rotation, revocation, and network destinations.
  8. Restrict the plugin allowlist and tool permissions to the minimum OneNote capabilities required.
  9. Require explicit user approval before plugin installation, account pairing, and write operations.
  10. Provide integrity-verification and incident-response instructions, including immediate token revocation and plugin removal.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.