Back to skill

Security audit

OpenAI

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent, but it should be reviewed carefully because it installs and allowlists an unpinned third-party plugin that handles OpenAI API credentials and broad account actions.

Install only if you trust the ClawLink plugin and are comfortable giving it access to your OpenAI API key and connected OpenAI account resources. Prefer a dedicated OpenAI project or limited API key with spending limits and audit logging, and confirm destructive or costly operations before execution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:46
Finding

Unpinned Third-Party Plugin Is Installed and Granted Tool Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 46–50
Vulnerability Type: Unpinned and unauditable third-party dependency
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The Skill instructs the agent to install clawhub:clawlink-plugin without specifying an immutable version, package digest, checksum, or signature verification step. It then explicitly adds the plugin to the allowed-tools configuration and restarts the OpenClaw gateway, causing the newly installed component to be loaded.

The plugin source is not included in the audited project, so its implementation and effective permissions cannot be verified from this repository. Because the package reference is mutable, the code installed at execution time may differ from the code originally reviewed. This creates a supply-chain trust gap, particularly because the plugin participates in OpenAI account pairing, credential handling, and API request proxying.

Attack Path

  1. An attacker compromises the plugin publisher account, package registry, distribution infrastructure, or a mutable future plugin release.
  2. A user invokes the Skill and approves installation.
  3. The agent installs the current package resolved by clawhub:clawlink-plugin, without checking an immutable digest or signature.
  4. The configuration command grants the plugin tool access.
  5. The gateway restart loads and activates the compromised plugin.
  6. During pairing or subsequent OpenAI operations, the plugin can potentially intercept credentials, alter requests or responses, invoke accessible tools, or transmit account data within the limits of its runtime privileges.

Impact Assessment

Successful exploitation could provide attacker-controlled plugin code with the privileges assigned to OpenClaw ...[truncated 711 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specific, audited version and preferably an immutable content digest.
  2. Verify a publisher signature and package checksum before installation; abort on verification failure.
  3. Publish the plugin source and reproducible-build instructions so the installed artifact can be independently audited.
  4. Display the resolved version, digest, publisher identity, requested permissions, and affected configuration before requesting user approval.
  5. Grant only the minimum tools and permissions required for OpenAI integration rather than broadly allowlisting the plugin.
  6. Run the plugin in a sandbox with restricted filesystem, network, process, and credential access.
  7. Scope OpenAI credentials to a dedicated project or service account with minimum privileges, spending limits, and audit logging.
  8. Add an explicit rollback procedure that disables the plugin, restores the previous configuration, and restarts the gateway safely.
  9. Continuously monitor the dependency for ownership changes, revoked signatures, reported compromises, and unexpected digest changes.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.