T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Is Granted Trusted Tool Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–49; repeated configuration commands at lines 290–291
Vulnerability Type: Unpinned third-party dependency with privileged integration access
Risk Level: MediumVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartThe relevant configuration and restart operations are repeated later:
bash openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The skill directs the user or agent to install
clawhub:clawlink-pluginwithout pinning a reviewed version or cryptographic digest. It then adds the plugin to OpenClaw's tool allowlist and restarts the gateway so that the plugin becomes active.This creates a supply-chain trust boundary: the effective implementation is obtained separately from the audited skill and may change after this file has been reviewed. The project does not include the plugin source, an integrity hash, a locked version, or a permission manifest that would allow its behavior to be verified as part of this audit.
The plugin's access is security-sensitive because the skill states that ClawLink stores the user's Airtable OAuth token, injects it into API requests, and proxies those requests. Consequently, an unexpectedly changed or compromised plugin release could operate within the user's OAuth-authorized Airtable scope.
Attack Path
- An attacker compromises the plugin publisher account, package registry entry, distribution infrastructure, or another component of the plugin's supply chain.
- The attacker publishes a malicious release under the mutable
clawlink-pluginidentifier. - A user follows the skill instructions and installs the plugin without a fixed version or integrity check.
- The configuration command adds the plugin to the trusted tool allowlist.
- Restartin ...[truncated 1434 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a specifically reviewed, immutable version rather than installing a mutable package identifier.
- Verify the package with a publisher signature or cryptographic digest before installation.
- Publish and review the corresponding source code, build provenance, release artifacts, and software bill of materials.
- Present a permission manifest before installation that identifies local capabilities, network destinations, credential access, and available Airtable operations.
- Require separate, explicit user approval before installing the plugin, modifying the tool allowlist, or restarting the gateway.
- Apply least privilege to both OpenClaw tool permissions and Airtable OAuth scopes. Avoid granting schema modification or destructive-operation scopes unless required.
- Restrict network communication to documented ClawLink and Airtable endpoints where the platform supports egress controls.
- Preserve confirmation enforcement outside the plugin so a plugin cannot unilaterally bypass approval for write or destructive operations.
- Document how to revoke Airtable OAuth access, unpair ClawLink, remove the allowlist entry, uninstall the plugin, and rotate affected credentials.
- Re-audit every plugin update before changing the pinned version.
