T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Installation and Allowlisting
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–49
Vulnerability Type: Unpinned and externally maintained plugin dependency
Risk Level: MediumVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartThe permission change and restart are also repeated in
SKILL.md, lines 296–297:bash openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The skill instructs users to install
clawhub:clawlink-pluginwithout selecting an immutable version or verifying a package signature, checksum, or source revision. It then explicitly allowlists the plugin and restarts the gateway, causing the externally maintained component to be loaded with plugin capabilities.Because this repository contains only
SKILL.md, the plugin implementation and its credential-handling behavior are outside the audited scope. The mutable package reference means that code retrieved during a future installation may differ from the code originally reviewed. This creates a supply-chain trust boundary in which compromise of the package, publisher account, distribution service, or dependency resolution process could deliver unauthorized code.The documentation also states that ClawLink stores an OAuth token and injects it into ActiveCampaign requests. This is transparent rather than hidden behavior, but it increases the potential consequences of a compromised plugin.
Attack Path
- An attacker compromises the plugin publisher account, package-distribution channel, or an upstream component used by the plugin.
- The attacker publishes a malicious release under the mutable
clawhub:clawlink-pluginidentifier. - A user follows the skill instructions and installs the package without an immutable version or integrity verification.
...[truncated 1037 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an audited, immutable version or content-addressed revision rather than installing a mutable package identifier.
- Verify a cryptographic signature or publisher-provided checksum before installation.
- Document the expected publisher identity, package version, digest, and trusted distribution origin.
- Publish or vendor the exact plugin source so its code, dependencies, network behavior, and credential handling can be independently audited.
- Apply least privilege by allowing only the specific tools required for ActiveCampaign tasks rather than broadly enabling the entire plugin where the platform supports granular controls.
- Require explicit user approval before installation, configuration modification, gateway restart, OAuth connection, and sensitive write operations.
- Isolate the plugin process and restrict filesystem, environment-variable, network, and credential access to the minimum necessary.
- Maintain dependency scanning, release signing, provenance attestations, and a documented revocation process for compromised releases.
