Back to skill

Security audit

Postmark Email

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently sets up a ClawLink-based Postmark integration with account credentials and write-capable Postmark tools, which matches its stated purpose.

Install this only if you trust ClawLink and the ClawHub plugin source with your Postmark server access. Use a narrowly scoped, revocable Postmark token if possible, review write previews carefully, and revoke the Postmark credential or remove the plugin if you no longer need the integration.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Is Granted Tool Access and Postmark Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–49 and 71–77
Vulnerability Type: Unpinned privileged third-party dependency
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart
markdown
**No API key is required in chat.** ClawLink stores the API key securely and injects it into every Postmark API request on the user's behalf.

### Getting Connected

1. Install the ClawLink plugin (see Install above).
2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.
3. Open https://claw-link.dev/dashboard?add=postmark and connect Postmark.

Technical Analysis

The setup installs clawlink-plugin without specifying an immutable version, package digest, or other locally verifiable integrity constraint. It then explicitly adds that plugin to OpenClaw's tool allowlist and restarts the gateway, activating the installed component.

The integration is subsequently entrusted with the user's Postmark API key and acts as a proxy for credential-backed Postmark operations. The audited project contains only SKILL.md; it does not include the plugin source, a dependency lockfile, a checksum, or signed provenance data. Consequently, the exact code installed at setup time cannot be verified from this artifact and could change independently after the Skill has been reviewed.

This creates a supply-chain trust boundary: compromise or unauthorized replacement of the package, its distribution account, or its delivery infrastructure could cause users to install attacker-controlled code with permitted tool access. The documented preview and confirmation workflow can govern compliant tool use, but it cannot constrain malicious behavior inside the trusted plugin itself.

Attack Path

  1. An attacker compromises or replaces the unpinned clawlink-plugin package or its distribution channel. ...[truncated 1479 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an immutable, reviewed version rather than installing an unconstrained package name.
  2. Verify the package with a cryptographic digest or trusted signature before installation.
  3. Document the expected publisher identity, release version, checksum, and provenance.
  4. Require explicit reapproval whenever the plugin version, digest, publisher, or requested permissions change.
  5. Review or vendor the exact plugin source distributed with the Skill so its behavior can be audited alongside SKILL.md.
  6. Restrict OpenClaw tool permissions and Postmark API scopes to the minimum capabilities required.
  7. Prefer short-lived, revocable, narrowly scoped authorization over a reusable server API key where supported.
  8. Provide a documented removal and credential-revocation procedure for suspected compromise.
  9. Keep write-operation preview and confirmation controls, but enforce them in a trusted host boundary rather than relying solely on the plugin to comply.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.