Back to skill

Security audit

PandaDoc Documents

Security checks for vulnerabilities and agentic risk

Overview

This PandaDoc skill is purpose-aligned but asks users to activate a third-party plugin and route sensitive PandaDoc OAuth access through ClawLink, so it should be reviewed before installation.

Install only if you trust ClawLink with your PandaDoc account. Before connecting, confirm the plugin publisher and version, review the PandaDoc permissions being granted, prefer least-privilege access where available, and be careful with write actions such as sending documents, deleting contacts or templates, uploading attachments, and creating webhooks.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:48
Finding

Unpinned Third-Party Plugin Installation and Activation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 48-52
Vulnerability Type: Unpinned and unverifiable third-party dependency installation
Risk Level: High

Vulnerable Code:

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The skill instructs users to install clawlink-plugin from a third-party package registry without pinning an immutable version, package digest, source revision, or verified signature. It then adds that plugin to the OpenClaw tool allowlist and restarts the gateway, causing the downloaded code to be activated.

The plugin implementation is not included in the audited project, which contains only SKILL.md. Consequently, its runtime behavior, dependency chain, credential handling, and update behavior cannot be verified from the available artifact. A mutable package reference allows the code installed in the future to differ from the code that may have been reviewed when the skill was published.

Attack Path

  1. An attacker compromises the plugin publisher account, package registry, distribution infrastructure, or an unpinned transitive dependency.
  2. The attacker publishes a malicious version under the existing clawlink-plugin package identifier.
  3. A user follows the skill instructions and installs the package through the mutable clawhub:clawlink-plugin reference.
  4. The configuration command explicitly allowlists the plugin.
  5. The gateway restart loads and activates the compromised plugin.
  6. Malicious plugin code can act within the permissions granted to OpenClaw plugins, potentially intercepting tool calls, accessing integration data, or performing unauthorized operations.

Impact Assessment

Successful exploitation could provide execution within the OpenClaw plugin environment. The practical scope depends on the plugin sandbox an ...[truncated 399 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an immutable, reviewed version rather than installing a floating package reference.
  2. Verify a cryptographic digest or publisher signature before installation and fail closed if verification fails.
  3. Publish the plugin source and reproducible build instructions so the installed artifact can be matched to audited source code.
  4. Document all transitive dependencies and lock them to reviewed versions with integrity hashes.
  5. Require explicit user approval that clearly identifies the plugin publisher, version, requested permissions, and affected integrations before installation.
  6. Apply least-privilege restrictions to the plugin and prevent access to unrelated tools, credentials, files, and integrations.
  7. Avoid automatically restarting the gateway immediately after installation. Perform integrity and permission checks before activation.
  8. Establish controlled update behavior so later package releases are not installed or activated without a new review and user authorization.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:76
Finding

Broad Delegation of PandaDoc OAuth Credentials and API Operations to a Third-Party Proxy

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 76-86; supporting architecture description at lines 9-11 and 34-35
Vulnerability Type: Excessive third-party access to credentials and sensitive integration operations
Risk Level: High

Relevant Code and Instructions:

markdown
This skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=pandadoc-documents) for hosted connection flows and credentials so you do not need to configure PandaDoc API access yourself.
text
│                      │  4. Secure Token      │
│                      │  5. Proxy Requests    │
markdown
## Authentication

All PandaDoc tool calls are authenticated automatically by ClawLink using the user's connected PandaDoc account.

**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every PandaDoc API request on the user's behalf.

### Getting Connected

1. Install the ClawLink plugin (see Install above).
2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.
3. Open https://claw-link.dev/dashboard?add=pandadoc and connect PandaDoc.
4. Call `clawlink_list_integrations` to verify the connection is active.

Technical Analysis

The skill delegates PandaDoc OAuth-token storage and all subsequent API requests to ClawLink, a third-party intermediary. This creates an additional privileged trust boundary between the user and PandaDoc. According to the documented tool inventory, the intermediary may facilitate access to documents, templates, folders, contacts, attachments, webhooks, and document-signing workflows.

The audited artifact does not provide implementation code, exact OAuth scopes, token encryption details, token retention rules, tenant-isolation controls, proxy endpoint restrictions, audit guarantees, or technical enforcement of the stated write-confirmation policy. Therefore, th ...[truncated 2310 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer direct PandaDoc OAuth integration where tokens remain under the user's or organization's control.
  2. If the proxy architecture is required, disclose the exact PandaDoc OAuth scopes before authorization and request only the minimum scopes necessary for each operation.
  3. Separate read and write authorization. Do not grant write, webhook, contact-management, or document-sending privileges unless the user explicitly enables them.
  4. Enforce write confirmation at a trusted technical boundary in the plugin or proxy, rather than relying solely on natural-language instructions.
  5. Use short-lived access tokens, secure refresh-token rotation, encrypted storage backed by a managed key service, and immediate revocation when an integration is disconnected.
  6. Document token retention, deletion, tenant isolation, administrator access, incident response, and audit-log policies.
  7. Restrict proxy endpoints so stored authorization cannot be used for arbitrary PandaDoc API requests outside the declared tool catalog.
  8. Provide users with complete logs of token use and sensitive operations, including the acting identity, target resource, parameters, timestamp, and confirmation record.
  9. Require renewed confirmation for high-impact actions such as sending documents, deleting resources, modifying contacts, uploading attachments, and creating webhooks.
  10. Subject the plugin and hosted proxy to independent security review, and publish sufficient implementation and architecture evidence to validate the stated controls.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.