T08 · Insecure Dependencies
- Location
SKILL.md:26- Finding
Unpinned Third-Party Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 26-28 and 39-43
Vulnerability Type: Supply-chain risk from a mutable, unpinned plugin dependency
Risk Level: MediumVulnerable Code
markdown ## Quick start 1. Install the verified ClawLink plugin: `openclaw plugins install clawhub:clawlink-plugin`markdown ### Installing the plugin If the ClawLink plugin is not installed yet, tell the user to run: openclaw plugins install clawhub:clawlink-pluginTechnical Analysis
The Skill instructs users to install
clawhub:clawlink-pluginwithout specifying an immutable version, package digest, signature, or other integrity constraint. The plugin contains executable behavior, but its source is not included in the audited project, which contains onlySKILL.md.Consequently, the code executed by this installation command may differ from the code reviewed when the Skill was published. A compromised publisher account, registry entry, distribution channel, or future malicious update could cause the same documented command to install attacker-controlled code.
The documentation calls the plugin “verified,” but it does not provide a verification procedure or cryptographic identity that users can independently validate.
Attack Path
- An attacker compromises the plugin publisher, package registry, release pipeline, or mutable plugin package.
- The attacker publishes a malicious release under the existing
clawhub:clawlink-pluginidentifier. - A user follows the Skill instructions and runs the unpinned installation command.
- OpenClaw resolves and installs the attacker-controlled version.
- The malicious plugin executes with the permissions available to OpenClaw plugins and can abuse accessible data, credentials, or tools.
This path is conditional on compromise or malicious replacement of the external dependency; the audited file does not itself demonstrate that the current ...[truncated 476 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a specific reviewed version and, where supported, an immutable cryptographic digest.
- Require signature verification and document the expected publisher identity, signing key, and verification procedure.
- Publish the exact plugin source or reproducible build artifact associated with the pinned release.
- Document the plugin permissions and reduce them to the minimum required for ClawLink operations.
- Configure update behavior so that new versions require explicit review and approval rather than being resolved implicitly.
- Add registry-integrity monitoring and a documented rollback procedure for compromised releases.
