T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Privileged Third-Party Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–49
Vulnerability Type: Unpinned third-party dependency with privileged tool access
Risk Level: MediumVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The skill instructs users to install
clawlink-pluginfrom ClawHub without specifying an immutable version, cryptographic digest, or signature-verification procedure. It then explicitly adds the plugin to the OpenClaw tool allowlist and restarts the gateway, activating whichever package the registry serves at installation time.The audited project contains no plugin source, lockfile, checksum, signature metadata, or reproducible-build information with which to verify the executable dependency. Consequently, the effective implementation can change independently of the reviewed
SKILL.mdfile.This creates a supply-chain trust gap. If the package registry, publisher account, distribution channel, or a later mutable release is compromised, malicious code could be delivered under the expected package name and receive the documented tool access after restart.
Attack Path
- An attacker compromises the ClawHub package entry, the publisher account, or the plugin distribution channel.
- The attacker publishes a modified package under the existing
clawlink-pluginidentifier. - A user follows the skill’s unpinned installation command.
- OpenClaw downloads the attacker-controlled package because no immutable version or digest is required.
- The user’s configuration allowlists the plugin.
- The gateway restart loads and activates the compromised plugin.
- The plugin abuses its tool access or OAuth-mediated Box connection to perform unauthorized operations within the connected account’s permissions.
Impact Assessment
A compromised plugin could operate with the OpenClaw tool acc ...[truncated 773 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a reviewed, immutable version rather than installing the floating package identifier.
- Require verification against a cryptographic digest or trusted publisher signature before installation.
- Publish the plugin source, dependency lockfile, release checksums, and reproducible-build instructions so the installed artifact can be independently audited.
- Enforce registry protections such as publisher identity verification, protected releases, multi-factor authentication, and signed provenance attestations.
- Grant only the minimum OpenClaw tools required for Box operations instead of broadly trusting the plugin.
- Separate read-only and write-capable permissions where possible, and keep destructive or administrative Box operations disabled unless explicitly needed.
- Present a clear security prompt before installation, allowlisting, gateway restart, and Box authorization.
- Monitor plugin-version changes and require renewed review and approval before upgrades.
- Provide a documented revocation procedure covering plugin removal, allowlist cleanup, OAuth-token revocation, and Box audit-log review.
