Back to skill

Security audit

Semrush

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed, read-only Semrush integration that uses ClawLink to hold the API key and proxy Semrush analytics requests.

Install only if you are comfortable connecting your Semrush API key to ClawLink and enabling the ClawLink plugin in OpenClaw. The documented Semrush operations are read-only, but requests can consume paid API units, especially large batches.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill instructs installation of a separate ClawLink plugin, changes local allowlist configuration, and restarts the OpenClaw gateway as part of using Semrush. Those actions expand the agent's available tooling and modify the host environment beyond the narrow SEO-analysis purpose, creating unnecessary attack surface and a path for privilege expansion or unintended tool access.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The troubleshooting section directs the agent to enumerate local plugins, alter configuration, and restart the gateway, which are administrative actions unrelated to retrieving Semrush analytics data. Even in a support context, embedding these commands in the skill encourages unnecessary system modification and can be abused to normalize broader local control by a data-access skill.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill states that ClawLink handles credentials and proxies Semrush requests, but it does not prominently warn that user queries and account-linked SEO data are transmitted through a third-party service. This creates a transparency and data-handling risk because users may believe they are interacting directly with Semrush when their data is actually routed via ClawLink.

VirusTotal

54/54 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.