Back to skill

Security audit

Slack

Security checks for vulnerabilities and agentic risk

Overview

This Slack skill is not clearly malicious, but it asks users to install and trust an external plugin and hosted OAuth intermediary with broad Slack read, write, file, and admin capabilities.

Review the ClawLink plugin publisher, requested Slack OAuth scopes, and revocation process before installing. Prefer a least-privilege Slack connection, avoid connecting highly sensitive workspaces unless you trust ClawLink as a credential intermediary, and confirm how to remove the plugin and revoke Slack access if no longer needed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:45
Finding

Unpinned Privileged Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 45-47; repeated configuration at lines 368-369
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The Skill directs the agent to install, explicitly allowlist, and activate the external clawlink-plugin. The plugin's implementation is not included in the audited project, and the installation command does not pin an immutable version or verify a cryptographic checksum.

Consequently, the code that ultimately processes credentials and performs Slack operations can differ from what was reviewed in this package. Restarting the gateway activates the unaudited dependency. Although the audit found no evidence that the referenced plugin is malicious, this design creates a supply-chain trust boundary that cannot be validated from the Skill itself.

Attack Path

  1. A user asks to enable the Slack Skill.
  2. The agent installs clawhub:clawlink-plugin without an immutable version or integrity check.
  3. The agent adds the plugin to tools.alsoAllow.
  4. The gateway is restarted, loading the externally supplied implementation.
  5. If the package source, publisher account, distribution infrastructure, or plugin release is compromised, attacker-controlled code runs with the plugin's granted tool access.
  6. The compromised plugin can intercept Slack requests, misuse connected credentials, or alter requested operations.

Impact Assessment

A compromised dependency could access data available through the connected Slack authorization, including messages, files, user information, and workspace metadata. Depending on granted OAuth scopes, it could also send or delete messages, modify channels, administer user groups, invite users, or access audit ...[truncated 172 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the plugin to a reviewed, immutable version rather than installing a mutable package reference.
  • Verify the package using a cryptographic digest or signed provenance record before installation.
  • Include the plugin source, permission manifest, and dependency lockfile in the review scope.
  • Require explicit, informed user approval before installation, allowlisting, and gateway restart.
  • Document the publisher-verification process and provide commands for disabling and uninstalling the plugin.
  • Run the plugin in a sandbox with narrowly constrained network, filesystem, process, and tool permissions.
  • Monitor installed plugin versions and alert users before upgrades change the reviewed implementation.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:67
Finding

Slack Credentials and Sensitive API Traffic Delegated to a Hosted Intermediary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 67-75
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Medium

Vulnerable Code:

markdown
All Slack tool calls are authenticated automatically by ClawLink using the user's connected Slack workspace OAuth token.

**No API token is required in chat.** ClawLink stores the OAuth token securely and injects it into every Slack Web API request on the user's behalf.

### Getting Connected

1. Install the ClawLink plugin (see Install above).
2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.
3. Open https://claw-link.dev/dashboard?add=slack and connect Slack.
4. Call `clawlink_list_integrations` to verify the connection is active.

Technical Analysis

The architecture delegates storage and use of the user's Slack OAuth token to the hosted ClawLink intermediary. All Slack API operations are consequently proxied through an additional party rather than being sent directly from the local agent to Slack.

This behavior is disclosed and network communication is required for Slack integration, so the audit did not identify covert exfiltration. Nevertheless, placing reusable OAuth credentials and request data under an intermediary's control expands the trust boundary beyond a direct Slack integration. The Skill does not identify exact OAuth scopes, retention periods, encryption controls, tenant-isolation measures, token-revocation procedures, or limits on intermediary access.

The statement that the token is stored “securely” is not supported by verifiable controls within the audited artifact.

Attack Path

  1. The user visits the ClawLink dashboard and authorizes access to a Slack workspace.
  2. ClawLink receives and stores the resulting Slack OAuth token.
  3. The installed plugin submits Slack operations through ClawLink.
  4. ClawLink injects the stored credential and proxies the requests t ...[truncated 780 chars]
Remediation
View remediation

Remediation Suggestions

  • Prefer direct Slack OAuth and API communication when a hosted credential intermediary is not necessary.
  • Display the exact requested OAuth scopes before the user authorizes the connection.
  • Request only the scopes needed for the user's selected functionality.
  • Separate read-only messaging access, file access, and administrative access into independently authorized scope bundles.
  • Publish verifiable controls for token encryption, retention, access logging, tenant isolation, incident response, and deletion.
  • Provide immediate token revocation and connection-removal procedures.
  • Use short-lived credentials or token exchange mechanisms where supported.
  • Ensure sensitive request and response bodies are excluded from routine logs and telemetry.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:145
Finding

Broad Sensitive Read, File-Publishing, and Administrative Capabilities Exceed Messaging-Only Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 145-166 and 207-217
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: High

Vulnerable Code:

markdown
### Conversations & History

| Tool | Description | Mode |
|------|-------------|------|
| `slack_fetch_conversation_history` | Get messages from a channel (main timeline, not threads) | Read |
| `slack_fetch_message_thread_from_a_conversation` | Get all replies in a specific thread | Read |
| `slack_list_conversations` | List conversations accessible to a user | Read |

### Users

| Tool | Description | Mode |
|------|-------------|------|
| `slack_list_all_users` | List all users in the workspace | Read |
| `slack_find_users` | Search users by name, email, or criteria | Read |
| `slack_find_user_by_email_address` | Look up a user by their email address | Read |
| `slack_get_user_presence` | Get a user's current presence (active/away) | Read |
| `slack_get_user_dnd_status` | Get a user's Do Not Disturb status | Read |

### Files

| Tool | Description | Mode |
|------|-------------|------|
| `slack_list_files_with_filters_in_slack` | List files shared in the workspace | Read |
| `slack_upload_file_to_channel` | Upload a file to a channel | Write |
| `slack_delete_file` | Permanently delete a file | Write |
| `slack_download_slack_file` | Download file content and get a public URL | Read |
markdown
### Team & Admin

| Tool | Description | Mode |
|------|-------------|------|
| `slack_fetch_team_info` | Get workspace metadata and settings | Read |
| `slack_invite_user_to_workspace` | Invite a new user to the workspace | Write |
| `slack_create_user_group` | Create a user group (subteam) | Write |
| `slack_list_user_groups` | List all user groups | Read |
| `slack_disable_user_group` | Disable a user group | Write |
| `slack_enable_user_group` | Re-enable a disabled u
...[truncated 2684 chars]
Remediation
View remediation

Remediation Suggestions

  • Default to a minimal messaging-only permission bundle.
  • Make conversation history, user-directory access, presence data, files, audit logs, and administration separate opt-in modules.
  • Obtain explicit user confirmation before sensitive reads, not only before writes.
  • Require separate elevated authorization for workspace invitations, user-group administration, audit logs, and Enterprise Grid operations.
  • Show the target channel, user, file, and intended data destination during confirmation.
  • Do not generate public file URLs by default; use authenticated, short-lived links with the narrowest possible audience.
  • Enforce confirmation and scope restrictions in plugin code rather than relying only on natural-language instructions.
  • Record security-relevant operations in an auditable log without storing message bodies, credentials, or file contents.
  • Revoke unused OAuth scopes when optional capability modules are disabled.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 388)May include surrounding context.

md
## Resources

- [Slack API Documentation](https://api.slack.com/)
- [Slack Web API Reference](https://api.slack.com/methods)
- [Slack Rate Limits](https://api.slack.com/docs/rate-limits)
- ClawLink: https://claw-link.dev

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 389)May include surrounding context.

md
## Resources

- [Slack API Documentation](https://api.slack.com/)
- [Slack Web API Reference](https://api.slack.com/methods)
- [Slack Rate Limits](https://api.slack.com/docs/rate-limits)
- ClawLink: https://claw-link.dev

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 390)May include surrounding context.

md
## Resources

- [Slack API Documentation](https://api.slack.com/)
- [Slack Web API Reference](https://api.slack.com/methods)
- [Slack Rate Limits](https://api.slack.com/docs/rate-limits)
- ClawLink: https://claw-link.dev

Static analysis

No suspicious patterns detected.