T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Is Granted Access to Credentials and Analytics Operations
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–49; related credential-flow context at lines 71–77
Vulnerability Type: Unpinned third-party dependency with privileged integration access
Risk Level: MediumComplete Code Snippet:
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartRelated credential-flow instructions:
markdown **No API key is required in chat.** ClawLink stores the API key securely and injects it into every Amplitude API request on the user's behalf. ### Getting Connected 1. Install the ClawLink plugin (see Install above). 2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet. 3. Open https://claw-link.dev/dashboard?add=amplitude and connect Amplitude. 4. Call `clawlink_list_integrations` to verify the connection is active.Technical Analysis
The Skill instructs users to install
clawhub:clawlink-pluginwithout pinning a version, immutable digest, or other verifiable artifact identifier. It then immediately adds that plugin to the OpenClaw tool allowlist and restarts the gateway so the component becomes active.The enabled component is trusted to participate in a hosted credential flow. According to the Skill, ClawLink stores the user's Amplitude API key and injects it into requests. The repository contains only
SKILL.md; it does not include the plugin implementation, a dependency lockfile, a checksum, signature-verification instructions, or other material that would allow the installed artifact to be matched to an audited version. The document's statement that the plugin is “verified” is therefore not independently substantiated by the reviewed project contents.This creates a supply-chain trust boundary: the code that ultimately runs and handles credentials may change after this Skill has been reviewed. Exploitation requir ...[truncated 1984 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a reviewed, immutable version and cryptographic digest instead of installing only by a mutable package name.
- Require package-signature and provenance verification before installation, and document the expected publisher identity and artifact hash.
- Include or link to auditable source corresponding exactly to the pinned release. Maintain a lockfile or manifest recording the verified artifact.
- Separate installation, allowlisting, and activation steps. Display the permissions and affected trust boundaries, then obtain informed user approval before enabling or restarting the gateway.
- Use a dedicated, least-privilege Amplitude credential restricted to the required project and operations. Avoid administrative or destructive permissions when only analytics reads are needed.
- Make write and destructive tools opt-in rather than granting them by default. Enforce confirmation outside the third-party plugin where possible.
- Document ClawLink's credential storage, encryption, retention, revocation, data-processing, and incident-response controls so users can evaluate the external processor.
- Support rapid credential revocation and plugin rollback. Rotate Amplitude credentials after suspected package or service compromise.
- Log plugin installation, tool invocation, credential use, and sensitive Amplitude operations to an independently protected audit destination.
