T08 · Insecure Dependencies
- Location
SKILL.md:54- Finding
Unpinned Privileged Third-Party Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14, 54–58, 73–80, and 111–112
Vulnerability Type: Unpinned third-party dependency with privileged OAuth-mediated access
Risk Level: MediumThe skill instructs the agent to install and explicitly allowlist a third-party plugin without pinning an immutable version or integrity hash:
markdown This skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=canva-designs) for hosted connection flows and credentials so you do not need to configure Canva API access yourself.bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartThe installed component is then entrusted with OAuth credentials and authenticated API requests:
markdown All Canva tool calls are authenticated automatically by ClawLink using the user's connected Canva account. **No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Canva API request on the user's behalf.The effective tool interface is also obtained dynamically:
markdown Tools are available dynamically from the live ClawLink catalog. Call `clawlink_list_tools --integration canva` to see the full list.Technical Analysis
The installation command identifies the plugin only as
clawhub:clawlink-plugin; it does not specify a fixed version, immutable package digest, signature requirement, or checksum. The plugin is subsequently added to the tool allowlist and loaded by restarting the gateway.This creates a supply-chain trust boundary that is not fully represented by the auditable project contents. The installed plugin can participate in authenticated Canva operations, while the remotely supplied live catalog determines which tools are exposed. Although the document describes ClawLink as verified and states that tokens are stored securely, the proje ...[truncated 2209 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a reviewed, immutable version rather than installing a floating package identifier.
- Verify the package using a cryptographic digest and publisher signature before installation.
- Publish or reference reproducible, reviewable source code for the exact plugin release.
- Document the plugin's local permissions, network destinations, OAuth scopes, token-storage model, and update behavior.
- Request only the minimum Canva OAuth scopes needed for the user's requested operation.
- Require explicit, informed user approval before installing the plugin, changing the tool allowlist, restarting the gateway, or initiating OAuth delegation.
- Avoid automatically completing installation and restart steps merely because the skill was invoked.
- Constrain the dynamic tool catalog to an approved set of Canva operations and reject newly introduced tools until reviewed.
- Isolate the plugin with least-privilege filesystem, process, and network permissions.
- Provide a revocation procedure covering Canva authorization, ClawLink pairing, plugin removal, and token invalidation.
- Record and surface the exact plugin version and integrity metadata in audit logs.
- Re-review the plugin and its exposed tool catalog before accepting updates.
