T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin with Broad OAuth-Backed Account Access
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent Outlook purpose, but it asks users to install and authorize a third-party ClawLink plugin with broad Microsoft account access without a pinned or verifiable plugin version.
Review the ClawLink plugin and OAuth consent carefully before installing. Use a limited Microsoft account if possible, confirm every send/delete/rule/calendar write action, and know how to revoke the Microsoft connected app and remove the plugin if you no longer need it.
SKILL.md:47Unpinned Third-Party Plugin with Broad OAuth-Backed Account Access
Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.
| Tool | Description | Mode |
|------|-------------|------|
| `outlook_add_mail_attachment` | Add an attachment to a message | Write |
| `outlook_create_attachment_upload_session` | Create an upload session for large attachments (>3 MB) | Write |
| `outlook_list_attachments` | List attachments on a message | Read |
### Rules & Categories
Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.
| Tool | Description | Mode |
|------|-------------|------|
| `outlook_add_mail_attachment` | Add an attachment to a message | Write |
| `outlook_create_attachment_upload_session` | Create an upload session for large attachments (>3 MB) | Write |
| `outlook_list_attachments` | List attachments on a message | Read |
### Rules & Categories
No suspicious patterns detected.