Back to skill

Security audit

Trello Projects

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Trello integration, but it asks users to permanently enable an external plugin and trust a hosted service with Trello OAuth access without enough detail about scope, pinning, or revocation.

Review ClawLink and the plugin before installing, confirm the Trello OAuth scopes shown during authorization, and be prepared to remove the plugin allowlist entry and revoke Trello access if you stop using it. Treat destructive Trello actions such as board, organization, card, webhook, or member changes as requiring explicit review.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Handles Trello OAuth Credentials and API Requests

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12, 33, 47–49, and 71–77
Vulnerability Type: Third-party supply-chain and credential-proxy trust risk
Risk Level: Medium

Complete Code Snippet

markdown
This skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=trello-projects) for hosted connection flows and credentials so you do not need to configure Trello API access yourself.
text
│                       │  5. Proxy Requests    │
bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart
markdown
**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Trello API request on the user's behalf.

### Getting Connected

1. Install the ClawLink plugin (see Install above).
2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.
3. Open https://claw-link.dev/dashboard?add=trello and connect Trello.
4. Call `clawlink_list_integrations` to verify the connection is active.

Technical Analysis

The skill directs users to install and explicitly allowlist an external plugin, restart the OpenClaw gateway, and authorize a hosted third-party service to store a Trello OAuth token and proxy API requests. The referenced plugin implementation is not present in the audited project, so its behavior cannot be independently verified from the available artifact.

The installation command does not pin an immutable plugin version, digest, or publisher signature. Consequently, the component installed in the future could differ from the component originally reviewed. The document describes the plugin as verified, but the audited instructions do not enforce integrity or provenance verification before installation.

Because the plugin is allowlisted as an Agent tool and the hosted service handles OAuth credentials, compromise of e ...[truncated 1753 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an immutable, reviewed version rather than installing an unqualified package reference.
  2. Require cryptographic verification through a trusted publisher signature and a documented package digest.
  3. Publish or link to the exact source revision corresponding to the installed artifact so the plugin can be independently audited.
  4. Display the requested Trello OAuth scopes before authorization and request only the minimum scopes needed for the selected operation.
  5. Document token storage, encryption, retention, rotation, revocation, incident-response, and tenant-isolation controls.
  6. Require explicit informed user consent before plugin installation, tool allowlisting, and OAuth authorization.
  7. Scope plugin access to the relevant skill or session instead of globally enabling it wherever platform controls permit.
  8. Provide clear instructions for uninstalling the plugin, removing it from tools.alsoAllow, disconnecting Trello, and revoking the OAuth token.
  9. Consider supporting a direct, locally configured Trello integration for users who do not want credentials or requests handled by an intermediary service.
  10. Re-audit the external plugin and hosted integration separately because their implementations are outside the supplied project.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.