T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Is Installed and Allowlisted
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47-49; related credential-handling context at lines 69-71
Vulnerability Type: Supply-chain risk from an unpinned executable dependency
Risk Level: MediumThe installation instructions contain the following complete command sequence:
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartThe associated authentication documentation states:
markdown **No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Bitbucket API request on the user's behalf.Technical Analysis
The Skill instructs the agent to install
clawhub:clawlink-pluginwithout specifying an immutable version, package digest, signature, or other integrity constraint. It then adds the plugin to the OpenClaw tool allowlist and restarts the gateway, causing executable behavior outside the reviewed Skill package to become available to the agent.Because the referenced plugin implementation is not included in this project, its behavior could not be audited. An unpinned package can resolve to a different implementation after this Skill has been reviewed. If the package distribution account, registry, release process, or latest package version were compromised, the installed plugin could execute attacker-controlled logic.
The Skill uses the plugin to communicate with a hosted intermediary that performs authenticated Bitbucket operations. Consequently, malicious plugin behavior could attempt unauthorized tool calls, alter request parameters, misrepresent responses, or abuse the connected account's repository permissions. The document's requirement for user confirmation before writes is a useful procedural control, but it does not establish the integrity of the plugin that implements or exposes those operations.
Attack Path
- An atta ...[truncated 1651 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a reviewed, immutable version rather than installing an unspecified current release.
- Verify the package with a cryptographic digest or publisher signature before installation.
- Document the expected publisher identity, package provenance, and verification procedure.
- Include the plugin source in the audit scope or provide a reproducible build and source-to-package attestation.
- Configure the Bitbucket OAuth connection with the minimum repository and write scopes required for the requested task.
- Separate read and write capabilities where supported, enabling write permissions only when needed.
- Enforce write confirmation outside the plugin itself so a compromised plugin cannot silently bypass that control.
- Run the plugin in a restricted sandbox with minimal filesystem, process, network, and credential access.
- Monitor authenticated Bitbucket operations and provide users with a clear way to revoke the integration immediately.
- Test and review dependency updates before changing the pinned version.
