Back to skill

Security audit

Telegram

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Telegram integration through ClawLink, with the main caution that setup installs and enables an external plugin.

Install only if you trust the ClawLink plugin and hosted service. Understand that ClawLink stores the Telegram bot token and proxies Telegram requests, and keep write-operation confirmations in place for sending, deleting, forwarding, moderation, and invite-link actions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:44
Finding

Unpinned Third-Party Plugin Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 44–51
Vulnerability Type: Unpinned executable third-party dependency
Risk Level: Medium

markdown
## Install

Install the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.

```bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart
text

### Technical Analysis

The Skill instructs the agent to install an executable third-party plugin using a mutable package identifier. It does not pin an audited version, specify a cryptographic digest, require publisher-signature validation, or provide another mechanism for verifying that the installed artifact matches the version reviewed with this Skill.

The subsequent configuration command explicitly permits the plugin, and the gateway restart loads it into OpenClaw. This makes the plugin part of the trusted execution boundary. Because the package reference is not immutable, the code retrieved at installation time may differ from the code that existed when the Skill was reviewed.

The installation also enables the general `clawlink-plugin` rather than documenting enforcement of a Telegram-only permission boundary. Although the Skill states that the plugin is verified and requires user confirmation before setup, those controls do not independently establish artifact integrity or constrain the plugin's runtime permissions.

### Attack Path

1. An attacker compromises the plugin publisher, its ClawHub account, the package registry, or the plugin's delivery pipeline.
2. The attacker publishes a malicious release under the existing mutable `clawhub:clawlink-plugin` identifier.
3. A user approves setup and the agent executes the documented installation command.
4. OpenClaw retrieves the attacker-controlled release because no immutable version or digest is specified.
5.
...[truncated 1326 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a specific, audited, immutable version rather than installing clawhub:clawlink-plugin without a version constraint.
  2. Publish and verify a cryptographic digest for the exact plugin artifact before installation.
  3. Require validation of a trusted publisher signature and fail closed if signature or digest verification fails.
  4. Document the package publisher, source repository, release provenance, and reproducible-build or attestation process.
  5. Review the plugin version's source code and transitive dependencies before recommending installation.
  6. Restrict plugin permissions to the minimum required Telegram capabilities. Where supported, allowlist only the necessary Telegram tools instead of the entire integration plugin.
  7. Clearly present the plugin's runtime permissions, data flows, external endpoints, and credential-handling model before requesting user consent.
  8. Keep explicit confirmation requirements for installation, gateway restart, and all write operations.
  9. Provide a removal and rollback procedure that disables the plugin, removes its allowlist entry, and revokes associated ClawLink and Telegram credentials.
  10. Re-audit and re-pin the artifact whenever upgrading rather than automatically accepting the latest available release.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.