Back to skill

Security audit

Google Calendar

Security checks for vulnerabilities and agentic risk

Overview

This Google Calendar skill is mostly coherent, but it should be reviewed because it installs and allowlists an unpinned third-party plugin that handles OAuth-backed calendar access.

Review the ClawLink plugin source, publisher, version, and verification status before installing. Use the smallest practical Google Calendar permission scope, confirm every calendar write or sharing change, and know how to remove the plugin and revoke the OAuth connection if needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Installation and Authorization

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–49
Vulnerability Type: Unpinned executable dependency loaded from a third-party package registry
Risk Level: Medium

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The skill instructs users to install clawlink-plugin without specifying an immutable version, cryptographic digest, or signature-verification procedure. It then adds that plugin to the OpenClaw tool allowlist and restarts the gateway, causing the registry-selected package revision to become active.

This creates a supply-chain trust dependency that cannot be fully assessed from the audited project because the plugin implementation is not included. A compromised registry, publisher account, package release, or distribution channel could replace the expected dependency with attacker-controlled code after this skill has been reviewed.

The risk is amplified by the plugin's intended role. The document states that ClawLink stores the user's OAuth token and injects it into proxied Google Calendar requests. The documented tool catalog includes access to calendar data and write operations such as creating or deleting events, changing access-control rules, and clearing calendars. The audit did not find evidence that the current plugin is malicious; the issue is the mutable, unverified installation mechanism.

Attack Path

  1. An attacker compromises the package publisher, registry, or another part of the plugin distribution chain.
  2. The attacker publishes a malicious release under the expected clawlink-plugin package identity.
  3. A user follows the skill instructions and installs the dependency without an immutable version or digest.
  4. OpenClaw resolves and installs the compromised release.
  5. The user adds the plugin to tools.alsoAllow.
  6. Restarting the gateway loads the attacker-controlled ...[truncated 909 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed, immutable version rather than installing the registry's current release.
  2. Verify the package with a cryptographic digest or trusted publisher signature before installation.
  3. Publish the expected version, digest, signing identity, source repository, and reproducible-build information in the skill documentation.
  4. Require explicit user approval before installing the plugin, modifying the tool allowlist, and restarting the gateway.
  5. Run the plugin with the least possible privileges, including narrowly scoped OAuth permissions and restricted filesystem, process, network, and secret access.
  6. Separate read-only calendar functionality from write and access-control functionality where supported.
  7. Retain the documented preview and confirmation requirements for all calendar writes, while enforcing them outside the potentially compromised plugin wherever possible.
  8. Audit plugin updates before deployment and prevent unattended upgrades to unreviewed releases.
  9. Provide revocation and incident-response instructions covering plugin removal, OAuth-token revocation, calendar permission review, and gateway restart.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

md
- Timezone-aware scheduling: Always use IANA timezone identifiers (e.g., `America/New_York`, `Europe/London`) not abbreviations.
- UTC timestamps ending in `Z` are interpreted in UTC regardless of calendar timezone — use timezone-offset timestamps for local date queries.
- Primary calendar is referenced as `calendar_id: "primary"`.
- Events with attendees automatically send invitations via Google Calendar.
- Deleting or moving events with attendees affects their calendars too — always confirm.
- No conflict checking is performed before event creation — use `find_free_slots` to detect overlaps.

Static analysis

No suspicious patterns detected.