T08 · Insecure Dependencies
- Location
SKILL.md:54- Finding
Unpinned Third-Party Plugin Handles Slack OAuth Access
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Slack helper is not clearly malicious, but it asks for broader local and third-party authority than its basic Slack purpose needs.
Review this carefully before installing. Use it only with a Slack workspace and channels where automated posting is acceptable, verify the ClawLink plugin identity and requested OAuth scopes, and revoke the OAuth grant if no longer needed. Avoid running the agent as administrator and require a manual check of the channel ID and message text before any post.
SKILL.md:54Unpinned Third-Party Plugin Handles Slack OAuth Access
SKILL.md:25Excessive Local Tool Permissions and Unsafe Privilege-Elevation Guidance
The manifest markets the skill as a limited Slack workspace integration, but declares broad read/write/exec tool access. Excess capability relative to the stated purpose violates least privilege and creates a larger attack surface if the skill is invoked with adversarial input or misunderstood by an agent.
The skill describes sending Slack messages but does not clearly emphasize that this is an external write action visible to workspace members. Without an explicit warning, an agent may post sensitive, incorrect, or premature content to a real channel, causing confidentiality or operational issues.
The operational instructions include a concrete send-message command but omit a direct caution to verify the recipient channel and message content first. This increases the risk of accidental posting to the wrong channel or publishing sensitive information, particularly because channel IDs are manually supplied.
The documentation explicitly promotes file read/write handling even though the skill's stated purpose is Slack workspace messaging and listing. Unjustified file capabilities can lead users or agents to expose local data or modify files without expecting that behavior from a Slack-focused skill.
The skill is presented as a narrowly scoped Slack workspace helper, but later sections advertise unrelated file handling and generic command-execution workflows. That scope drift can mislead an agent or operator into granting or using broader capabilities than necessary, increasing the chance of unintended file access or command execution under the guise of a Slack-only skill.
The manifest display name, summary, and description are presented in Chinese, and the rest of the skill documentation is also effectively Chinese-only. This imposes a specific language/locale without any opt-in, language-selection guidance, or documented reason for the restriction.
No suspicious patterns detected.