Back to skill

Security audit

Google Calendar

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Google Calendar integration, but it grants broad calendar write, sharing, hosted OAuth, and persistent plugin authority that users should review before installing.

Install only if you trust ClawLink with your Google Calendar OAuth access. Review the Google permission screen carefully, avoid granting broad write or sharing scopes unless needed, confirm every write or destructive action, and know how to disconnect both ClawLink and Google access before using it for sensitive calendars.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:49
Finding

Unpinned Third-Party Plugin Is Installed and Persistently Allowlisted

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:49-53
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart

Technical Analysis

The installation command identifies the ClawLink plugin only by its mutable registry name. It does not pin an exact version, content digest, verified signature, or immutable source revision. The subsequent command permanently adds the plugin to the allowed tool configuration, and the gateway restart loads it into the OpenClaw environment.

As a result, the code reviewed during this audit may differ from the code installed later. A compromised registry account, malicious package update, or supply-chain compromise could cause users to install altered plugin code without any corresponding change to this Skill file.

This is especially sensitive because the plugin mediates OAuth-authenticated Google Calendar operations, including reading event information and performing calendar write operations.

Attack Path

  1. An attacker compromises the plugin publisher, distribution registry, or release process.
  2. The attacker publishes a malicious release under the existing clawlink-plugin package name.
  3. A user follows the Skill instructions and runs the unversioned installation command.
  4. The mutable package reference resolves to the malicious release.
  5. The plugin is added to tools.alsoAllow, and the gateway restart loads it.
  6. The malicious plugin executes within its granted tool context and may intercept calendar data, OAuth-mediated requests, or calendar operations.

Impact Assessment

Exploitation could grant attacker-controlled plugin code access to the privileges available to the installed integration. Depending on the OAuth scopes and plugin runtime permis ...[truncated 575 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the plugin to an exact, reviewed version.
  • Verify the package using a cryptographic digest or trusted publisher signature before installation.
  • Publish a reproducible source repository and associate each release with a source commit.
  • Document the plugin's complete runtime permissions and requested Google OAuth scopes.
  • Apply least privilege by requesting only the calendar scopes required for the selected operations.
  • Avoid persistent global allowlisting when a session-scoped or narrowly scoped authorization mechanism is available.
  • Require explicit administrator approval before installation or upgrade.
  • Establish a controlled update process that reviews permission and behavior changes before deploying new releases.

other

Warning
Location
SKILL.md:10
Finding

OAuth Credentials and Sensitive Calendar Data Are Entrusted to a Hosted Intermediary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:10-11, 85-95
Vulnerability Type: Third-party credential custody and sensitive-data exposure
Risk Level: Medium

Relevant Code

markdown
This skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=google-calendar-scheduling) for hosted connection flows and credentials so you do not need to configure Google Calendar API access yourself.
markdown
## Authentication

All Google Calendar tool calls are authenticated automatically by ClawLink using the user's connected Google account.

**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Google Calendar API request on the user's behalf.

### Getting Connected

1. Install the ClawLink plugin (see Install above).
2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.
3. Open https://claw-link.dev/dashboard?add=google-calendar and connect Google Calendar.
4. Call `clawlink_list_integrations` to verify the connection is active.

Technical Analysis

The Skill explicitly routes Google Calendar authentication through ClawLink and states that ClawLink stores the user's OAuth token. Consequently, the hosted intermediary occupies the trust boundary between OpenClaw and Google Calendar and is technically positioned to process OAuth-authenticated requests and calendar responses.

This architecture creates a credential-custody and privacy risk beyond direct Google OAuth access. Calendar information may contain confidential meeting subjects, descriptions, attendee identities, availability, and access-control details. The audited file does not specify exact OAuth scopes, token retention periods, encryption controls, tenant-isolation measures, audit logging, or incident-response guarantees.

The Skill discloses the use of the intermediary, and the audited file contains no evidence that cre ...[truncated 1416 chars]

Remediation
View remediation

Remediation Suggestions

  • Prefer direct Google OAuth and direct API communication with locally protected token storage where feasible.
  • Clearly disclose every requested OAuth scope before the user authorizes the connection.
  • Use the narrowest possible OAuth scopes and separate read-only access from write or ACL-management access.
  • Encrypt OAuth tokens at rest with a dedicated key-management system and protect all traffic with modern TLS.
  • Implement strict tenant isolation, short-lived access tokens, refresh-token rotation, and immediate revocation support.
  • Document token retention, deletion, backup, logging, employee-access, and breach-notification policies.
  • Provide users with a simple method to disconnect the integration and revoke authorization at both ClawLink and Google.
  • Avoid logging event contents, attendee information, authorization headers, access tokens, or refresh tokens.
  • Subject the intermediary and OAuth implementation to independent security review and regular penetration testing.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest presents the skill as meeting scheduling and event management, but the tool reference includes destructive calendar-level operations such as deleting a secondary calendar and clearing all events. That mismatch can mislead users and higher-level agent policy about the true blast radius, enabling unexpectedly destructive actions under the guise of routine scheduling support.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description frames the capability as calendar viewing, scheduling, and event updates, but the documented toolset also exposes ACL management that can share calendars or revoke access. This is a scope expansion beyond user expectations, increasing the risk that an agent or user may authorize or invoke sensitive sharing operations without understanding that access-control changes are in scope.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

md
- Timezone-aware scheduling: Always use IANA timezone identifiers (e.g., `America/New_York`, `Europe/London`) not abbreviations.
- UTC timestamps ending in `Z` are interpreted in UTC regardless of calendar timezone — use timezone-offset timestamps for local date queries.
- Primary calendar is referenced as `calendar_id: "primary"`.
- Events with attendees automatically send invitations via Google Calendar.
- Deleting or moving events with attendees affects their calendars too — always confirm.
- No conflict checking is performed before event creation — use `find_free_slots` to detect overlaps.

Static analysis

No suspicious patterns detected.