Back to skill

Security audit

Zulip

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Zulip integration, but it recommends installing an unpinned third-party code plugin that would handle credentials and potentially administrative Zulip actions.

Review the exact @niyazmft/openclaw-zulip plugin version before installing, prefer a pinned or verified release, and use a dedicated least-privilege Zulip bot account. Keep enableAdminActions disabled unless needed, and require explicit approval before stream/user changes or outbound messages in sensitive workspaces.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–20
Vulnerability Type: Unpinned external dependency installation
Risk Level: Medium

Vulnerable Code Snippet:

markdown
> ⚠️ **DEPRECATED**: This skill is superseded by the `@niyazmft/openclaw-zulip` code plugin.
>
> Install the plugin directly with:
> ```
> openclaw plugins install clawhub:@niyazmft/openclaw-zulip
> ```

Technical Analysis

The installation command retrieves an externally maintained plugin from ClawHub without specifying a fixed version, immutable digest, checksum, or signature verification requirement. Consequently, the artifact installed by this command may differ from the artifact that was available when this skill was reviewed.

This project does not contain the plugin's source code, so the behavior of the installed component is outside the scope of the audited package. Because the plugin provides Zulip integration, it may legitimately receive access to configured Zulip credentials, messages, media uploads, and enabled administrative operations. Compromise of the publisher account, package registry, distribution process, or a later plugin release could therefore introduce malicious code through this unpinned dependency.

Attack Path

  1. An attacker compromises the plugin publisher account, the ClawHub registry entry, or the plugin's release pipeline.
  2. The attacker publishes a modified release under @niyazmft/openclaw-zulip.
  3. A user follows the documented installation command without a version or digest constraint.
  4. ClawHub resolves and installs the attacker-controlled release.
  5. The plugin executes within the OpenClaw environment and can attempt to access resources available to that process.
  6. Depending on the configured permissions, the malicious plugin could misuse Zulip credentials, read or send messages, process uploaded media, or invoke enabled administrative functionality.

...[truncated 716 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to a reviewed, explicit version rather than resolving the latest available release.
  2. Prefer an immutable package digest or content hash when supported by the package manager.
  3. Verify package signatures and checksums before installation.
  4. Document the plugin's authoritative source repository and publisher identity.
  5. Review the exact plugin source and release artifact before deployment.
  6. Use a dedicated Zulip bot account with only the permissions required for intended operations.
  7. Keep enableAdminActions disabled unless administrative functionality is strictly necessary.
  8. Isolate the plugin runtime and restrict its filesystem, network, process, and credential access.
  9. Establish dependency monitoring and require manual review before upgrading to a new plugin release.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
This skill provides the intelligence and instructions for interacting with the Zulip communication platform through the OpenClaw Zulip Bridge plugin.

## Capabilities
- **Messaging**: Send messages to Zulip streams, topics, or direct messages.
- **Stream Management**: Create, edit, and list Zulip streams.
- **User Actions**: Invite users to streams and check user presence.
- **Reactions**: Add or remove emoji reactions to messages.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly supports administrative actions and instructs users to place Zulip credentials in a local configuration file, but it does not warn about the sensitivity of those credentials or the potential consequences of privileged actions. In an agent setting, this omission increases the chance of unsafe deployment, over-privileged configuration, or unintended destructive actions against a Zulip workspace.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.