Security audit
TripHelm
Security checks for vulnerabilities and agentic risk
Overview
TripHelm is a disclosed travel-planning connector that can manage trips in the user's TripHelm account, with no evidence of hidden or unrelated behavior.
Install only if you want OpenClaw to connect to TripHelm and manage trips in your authorized account. The skill can read, create, edit, search, and delete TripHelm itinerary data, and OAuth offline access may allow continued access until you revoke it; do not paste credentials into chat and review destructive trip changes before approving them.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
