T08 · Insecure Dependencies
- Location
skill.md:121- Finding
Execution of an Unpinned Third-Party Plugin Patch
- Content
View full analysis
Vulnerability Details
File Location:
skill.md, lines 37 and 121-125
Vulnerability Type: Third-party supply-chain risk
Risk Level: MediumVulnerable Code
Installation command at line 37:
bash openclaw plugins install @tencentdb-agent-memory/memory-tencentdbPatch execution instructions at lines 121-125:
bash cd ~/.openclaw/extensions/memory-tencentdb bash scripts/openclaw-after-tool-call-messages.patch.sh openclaw gateway restartTechnical Analysis
The instructions install a third-party package without pinning an exact version or requiring signature, checksum, provenance, or source verification. They subsequently direct the user to execute a shell script supplied by that package.
The patch script is not included in the audited project, so its behavior cannot be statically verified. Because it is described as changing the handling of tool-call messages, it may modify security-sensitive OpenClaw behavior and gain access to tool outputs. A mutable or compromised package version could therefore execute arbitrary commands with the installing user's privileges.
The issue is not evidence that the named package is currently malicious. The vulnerability is the unsafe trust and execution model imposed by the installation instructions.
Attack Path
- An attacker compromises the package publisher, registry account, distribution infrastructure, or a future package release.
- The user follows the Skill and installs the package without an exact version or integrity verification.
- The compromised package is placed under
~/.openclaw/extensions/memory-tencentdb. - The user executes
scripts/openclaw-after-tool-call-messages.patch.sh. - Attacker-controlled shell commands run with the user's privileges.
- The script modifies OpenClaw files or tool-call handling.
- The Gateway restart activates the modified behavior in subsequent sessions.
Impact Assessment
Successful exploitation could provide arbitrary code exec ...[truncated 639 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a specific reviewed version rather than accepting the latest available release.
- Document the authoritative registry namespace and source repository.
- Require cryptographic checksum or signature verification before installation.
- Review and vendor the required patch script within the Skill so its contents are covered by the audit.
- Display or inspect the patch before execution and fail closed if it differs from the reviewed version.
- Run the plugin and patch under a dedicated, unprivileged account with narrowly scoped filesystem access.
- Prevent the extension from accessing credentials or unrelated conversation data unless explicitly required.
- Back up affected files and verify the exact modifications before restarting the Gateway.
- Prefer a supported OpenClaw API or versioned integration mechanism over patching installed application behavior.
