Back to skill

Security audit

Google Sheets

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Google Sheets integration, but it asks users to install and allowlist an unpinned third-party plugin that handles Google OAuth and spreadsheet reads/writes.

Review this before installing: it will connect a Google account through ClawLink, allow spreadsheet reads, and enable confirmed writes or destructive changes. Install only if you trust the ClawLink plugin source, verify the Google consent screen and requested scopes, require previews before writes, and know how to revoke the Google connection and remove the plugin if you stop using it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:42
Finding

Unpinned Third-Party Plugin Is Granted Access to OAuth-Mediated Spreadsheet Operations

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 42–50 and 71–79
Vulnerability Type: Unpinned and unauditable third-party dependency
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

The same file describes the plugin's authentication role:

text
All Google Sheets tool calls are authenticated automatically by ClawLink using the user's connected Google account.

No API key is required in chat. ClawLink stores the OAuth token securely and injects it into every Google Sheets API request on the user's behalf.

Technical Analysis

The installation command identifies clawlink-plugin only by a mutable registry name. It does not pin an immutable version or cryptographic digest, verify a publisher signature, or provide locally auditable plugin source code. The instructions then add that plugin to the tool allowlist and restart the gateway so that it is loaded.

This creates a supply-chain trust gap: the behavior installed at execution time can differ from the artifact reviewed in this audit. The dependency occupies a sensitive boundary because it supports a hosted OAuth flow and proxies operations against spreadsheets in the connected Google account.

The reviewed file explicitly discloses this architecture and requires user confirmation for write operations. There is no evidence that the current package steals credentials or intentionally misuses data. The risk arises from the inability to establish that the subsequently downloaded plugin is immutable and equivalent to a reviewed implementation.

Attack Path

  1. An attacker compromises the plugin publisher account, distribution registry, build pipeline, or an upstream component used by clawlink-plugin.
  2. The attacker publishes a modified artifact under the same unversioned plugin name.
  3. A user follows SKILL.md and runs `opencla ...[truncated 1265 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an immutable, reviewed version rather than installing it only by package name.
  2. Verify a cryptographic digest and publisher signature before installation.
  3. Publish the corresponding plugin source code and provide reproducible-build instructions so reviewers can verify that the distributed artifact matches the source.
  4. Maintain a signed software bill of materials and continuously scan the plugin and its transitive dependencies.
  5. Grant only the minimum Google OAuth scopes required for the requested spreadsheet operation.
  6. Document token storage, encryption, retention, access controls, revocation, and incident-response procedures.
  7. Isolate the plugin with restrictive filesystem, process, and outbound-network permissions.
  8. Preserve explicit user approval before installation, account pairing, and every write operation.
  9. Show the target spreadsheet, range, operation, and proposed values in a preview before requesting write approval.
  10. Provide a straightforward procedure to revoke the Google connection, remove the plugin allowlist entry, and uninstall the plugin.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.