T08 · Insecure Dependencies
- Location
SKILL.md:74- Finding
Unpinned Third-Party Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 74-76
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code
markdown **Lossless Claw** (`@martian-engineering/lossless-claw`) — compacts old context into expandable summaries to prevent amnesia. Install separately: `openclaw plugins install @martian-engineering/lossless-claw`Technical Analysis
The documented installation command does not specify an exact package version, trusted artifact digest, or signature. Consequently, users following this instruction may install whichever package version is current at installation time rather than the version represented during this audit.
This creates a supply-chain risk: compromise of the package publisher, registry account, publication process, or a later malicious release could cause the OpenClaw plugin manager to install code that has not been reviewed. The plugin is explicitly optional and is not installed by
scripts/setup_memory_v2.sh, so exploitation requires a user or administrator to follow the separate installation instruction.Attack Path
- An attacker compromises the package publisher account, registry publication channel, or upstream release process.
- The attacker publishes a malicious version under
@martian-engineering/lossless-claw. - A user follows the unpinned command in
SKILL.md. - The plugin manager resolves and installs the attacker-controlled release.
- OpenClaw loads the plugin, allowing its code to execute within the permissions and environment of the OpenClaw process.
Impact Assessment
Successful exploitation could grant malicious plugin code the same privileges as the OpenClaw process. Depending on that process's configuration, the plugin could access or modify agent memory, alter agent behavior, read environment-accessible credentials, or communicate with external systems. The exact scope is limited by the operat ...[truncated 274 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an exact, reviewed version rather than resolving the latest available release.
- Use an integrity digest, cryptographic signature, or lockfile where supported by the OpenClaw plugin manager.
- Document the authoritative package registry and source repository so users can verify package provenance.
- Review the plugin's source and release artifacts before installation and before intentional upgrades.
- Run OpenClaw with least privilege, restrict unnecessary network access, and expose only required credentials and files.
- Keep the plugin explicitly optional and warn users that third-party plugin code executes with the OpenClaw process's permissions.
