Back to plugin

Security audit

ClawLink

Security checks for vulnerabilities and agentic risk

Overview

ClawLink is a disclosed third-party integration plugin that can read from and act in connected apps, with the expected credential storage and safety guidance for that purpose.

Install only if you are comfortable letting ClawLink mediate access to the external apps you connect. Review connected app scopes in the ClawLink dashboard, use previews for write actions, and be especially careful with email sending, public posting, CRM changes, payments, or deletions.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is broad enough to activate for many common requests involving Gmail, Slack, calendars, docs, and other external apps. Over-broad activation increases the chance the agent will invoke a high-privilege integration path unnecessarily, expanding access to connected third-party data and actions beyond what is minimally needed.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skills/clawlink-runtime/SKILL.md (reported line 50)May include surrounding context.

md
Use this skill when the user asks you to read from or act in an external app or service, such as Notion, Gmail, Outlook, ClickUp, Google Calendar, Apollo, or OneDrive. Use it only for that request. Do not call ClawLink for requests that do not involve an external app.

When the app is connected to ClawLink, use the ClawLink tools below instead of browser workarounds, and do not ask the user for separate per-app credentials.

## After pairing

Static analysis

No suspicious patterns detected.