Back to skill

Security audit

Slacrawl

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently helps search and refresh Slack archives, with sensitive Slack data access disclosed and bounded by its stated purpose.

Install only if you are comfortable letting the slacrawl binary access local Slack archive data and, when explicitly used, Slack API tokens. Prefer a pinned reviewed version instead of @latest in environments with sensitive Slack data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned Executable Dependency Installed from a Mutable Upstream Revision

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8–12
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code Snippet:

yaml
install:
  - kind: go
    module: github.com/openclaw/slacrawl/cmd/slacrawl@latest
    bins:
      - slacrawl

Technical Analysis

The installation configuration retrieves and builds the slacrawl executable using the mutable Go version selector @latest. The installed source revision can therefore change after this skill has been reviewed, without any corresponding modification to the audited project.

This creates a supply-chain risk because installation implicitly trusts whichever upstream release is considered latest at installation time. No immutable version, commit hash, checksum, or provenance verification is specified. If the upstream repository, maintainer account, release process, or dependency chain is compromised, an attacker could publish altered code that is subsequently installed under the expected slacrawl name.

This finding concerns dependency immutability and does not establish that the current upstream package is malicious.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, its release process, or a relevant dependency.
  2. The attacker publishes a malicious revision or release that resolves as github.com/openclaw/slacrawl/cmd/slacrawl@latest.
  3. A user or automated environment installs the skill dependency.
  4. The installer resolves @latest, downloads the changed source, builds it, and installs the resulting slacrawl executable.
  5. The skill later invokes commands such as slacrawl doctor, slacrawl status, slacrawl sync, or slacrawl search, causing the compromised executable to run with the invoking process's privileges.

Impact Assessment

Successful exploitation could allow arbitrary behavior within the privileges of the account that installs or exe ...[truncated 516 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with a reviewed, explicit semantic version or immutable commit identifier, for example:
    yaml
    module: github.com/openclaw/slacrawl/cmd/slacrawl@vX.Y.Z
    
  2. Establish a controlled update process that reviews upstream changes before advancing the pinned version.
  3. Verify release provenance, signatures, or checksums where supported by the installation framework.
  4. Generate and retain dependency metadata or a software bill of materials for the reviewed release.
  5. Install and execute the binary with least privilege, restricting filesystem, credential, and network access to what archive operations require.
  6. Avoid exposing Slack API tokens to the process unless API synchronization or protected thread/DM hydration is explicitly requested.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.