T08 · Insecure Dependencies
- Location
SKILL.md:174- Finding
Unverified and Unpinned Third-Party Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 174-188
Vulnerability Type: Third-party supply-chain exposure
Risk Level: MediumVulnerable Code
bash # Search for skills clawhub search "关键词" # Install a skill clawhub install 技能名 # Update all skills clawhub update --all # List installed skills clawhub listTechnical Analysis
The skill documentation directs the agent to install skills from ClawHub and bulk-update all installed skills. It does not require immutable version or digest pinning, publisher verification, package integrity validation, permission review, source inspection, or sandboxed testing before activation.
A marketplace skill is an external, mutable component that may contain instructions or executable resources. Consequently, the behavior reviewed at one point in time may differ from the behavior installed later. The
clawhub update --allcommand further expands this risk by replacing multiple previously installed or reviewed components without requiring an individual security decision for each update.The project does not itself contain a malicious payload, and exploitation depends on a malicious or compromised third-party skill. Nevertheless, its documented installation process creates an unsafe supply-chain path.
Attack Path
- An attacker publishes a malicious skill, compromises an existing skill or publisher account, or supplies a deceptively named skill through ClawHub.
- A user asks the hub to search for or install a skill matching the attacker's package.
- The agent follows the documented workflow and executes
clawhub installwithout verifying an immutable version, digest, provenance, or requested permissions. - Alternatively,
clawhub update --allretrieves a malicious update for a previously trusted skill. - The external skill is registered in the OpenClaw workspace and becomes available to influence later agent operations.
- Whe ...[truncated 811 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit user confirmation before every third-party installation or update.
- Pin each approved skill to an immutable version and cryptographic digest rather than resolving a mutable package name.
- Verify package signatures, publisher identity, repository provenance, and integrity metadata before installation.
- Maintain an allowlist of reviewed publishers, package names, versions, and hashes.
- Download packages into a quarantine directory and audit their instruction files, scripts, dependencies, hooks, and requested permissions before activation.
- Replace
clawhub update --allwith individually reviewed and version-pinned updates. - Run newly installed skills in a restricted sandbox with minimal filesystem, network, credential, command-execution, and tool permissions.
- Record installation provenance and retain a known-good version to support rollback.
- Re-audit every update, even when its package name or publisher has previously been approved.
