Back to skill

Security audit

Semrush

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Semrush analytics integration, but it asks users to install and enable a mutable third-party plugin that handles their Semrush API key through an external service.

Install only if you are comfortable trusting ClawLink with your Semrush API key and trusting the installed plugin after gateway restart. Prefer a dedicated, revocable Semrush API key, monitor API-unit consumption, and review the ClawLink plugin/package version and permissions before enabling it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:48
Finding

Unpinned Third-Party Plugin Installation and Activation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 48-50
Vulnerability Type: Unpinned executable dependency
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The installation command identifies the third-party plugin only by its mutable package name. It does not specify an audited version, immutable artifact digest, signature, or integrity checksum.

The subsequent commands add the plugin to the allowed tool configuration and restart the OpenClaw gateway, causing the downloaded executable component to be loaded. Consequently, the code that ultimately executes can differ from the version reviewed when this skill was published.

No evidence establishes that the named plugin is currently malicious. The vulnerability is the unsafe supply-chain trust model: compromise of the package registry, publisher account, distribution infrastructure, or a later plugin release could cause altered code to be installed and activated.

Attack Path

  1. An attacker compromises the plugin publisher account, registry entry, or package distribution infrastructure.
  2. The attacker publishes a modified release under the existing mutable clawlink-plugin package name.
  3. A user follows the skill instructions and executes the unpinned installation command.
  4. OpenClaw resolves the package name to the attacker-controlled release.
  5. The configuration command enables the installed plugin.
  6. Restarting the gateway loads the altered plugin code.
  7. The malicious plugin operates with whatever process, filesystem, network, credential, and tool privileges are available to the OpenClaw plugin runtime.

Impact Assessment

Successful exploitation could permit arbitrary behavior within the OpenClaw plugin security context. Depending on runtime permissions, ...[truncated 438 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specific, reviewed version rather than installing a mutable package name.
  2. Pin an immutable artifact digest or checksum and verify it before activation.
  3. Require cryptographic package signatures and validate the expected publisher identity.
  4. Publish the expected version, digest, source repository, and verification procedure in the skill documentation.
  5. Review plugin permissions and source code before adding it to tools.alsoAllow.
  6. Request explicit user approval immediately before installation, configuration changes, and gateway restart.
  7. Run plugins in a least-privilege sandbox with restricted filesystem, network, environment-variable, and credential access.
  8. Establish an update-review process so newer plugin releases are not activated automatically without renewed security review.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:70
Finding

Broad Third-Party Credential and Live Tool-Catalog Trust

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 70-78; related trust instruction at line 219
Vulnerability Type: Excessive third-party trust and insufficient capability scoping
Risk Level: Medium

Vulnerable Code

markdown
All Semrush tool calls are authenticated automatically by ClawLink using your Semrush API key stored securely in the dashboard.

**No API key is required in chat.** ClawLink injects your API key into every Semrush API request on your behalf.

### Getting Connected

1. Install the ClawLink plugin (see Install above).
2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.
3. Open https://claw-link.dev/dashboard?add=semrush and connect Semrush with your API key.
4. Call `clawlink_list_integrations` to verify the connection is active.

The discovery workflow additionally instructs the agent at line 219:

markdown
3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.

Plugin activation is performed at lines 48-50:

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The skill delegates storage and use of the user's Semrush API key to the ClawLink hosted service. It also enables the complete clawlink-plugin rather than defining a local allowlist limited to fixed, reviewed Semrush read-only operations.

Tool capabilities are discovered dynamically, and the instructions designate the externally returned catalog as the source of truth. The audited project contains no plugin implementation, local schema pinning, capability restrictions, or policy enforcement that independently proves every dynamically returned tool remains read-only and limited to Semrush.

This does not prove that ClawLink currently mishandles credentials or serves unsafe tools. The risk arises because ...[truncated 1771 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace broad plugin authorization with a local allowlist containing only the exact Semrush tool identifiers required by this skill.
  2. Pin reviewed tool schemas and reject unexpected tools, permission changes, or incompatible schema revisions.
  3. Require explicit user confirmation whenever the live catalog adds a tool or expands an existing tool's capabilities.
  4. Use a dedicated, least-privilege, revocable Semrush API credential rather than a broadly privileged account key.
  5. Document credential encryption, retention, access controls, audit logging, breach response, revocation, and deletion procedures.
  6. Provide a direct mechanism for users to revoke the integration and permanently delete the stored API key.
  7. Ensure the plugin cannot read unrelated credentials, environment variables, files, or tool outputs.
  8. Independently enforce read-only Semrush endpoints in a fixed local policy rather than relying solely on externally supplied descriptions.
  9. Authenticate and integrity-protect catalog responses, and record catalog versions used for each operation.
  10. Warn users that API requests and credentials pass through a third party, and obtain informed consent before connection.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

md
1. For unfamiliar tools or ambiguous requests, call `clawlink_describe_tool` first.
2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.
3. All Semrush tools are read-only — no confirmation is required for data retrieval.
4. Parse CSV-formatted responses before structured use. Use `sep=';'` and cast numeric columns before aggregation.
5. A response of `ERROR 50 :: NOTHING FOUND` is a valid zero-result — not a system error.
6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.

Static analysis

No suspicious patterns detected.