T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Unpinned Third-Party Plugin Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:29-34
Vulnerability Type: Unpinned third-party plugin installation
Risk Level: MediumTechnical Analysis
The setup instructions require installation of a third-party plugin by a mutable registry identifier, without specifying a version, integrity hash, verified publisher identity, or reviewed source revision:
markdown **Step 1** — Install the ClawLink plugin:text openclaw plugins install clawhub:clawlink-pluginmarkdown Start a fresh chat after installing.Installing
clawhub:clawlink-pluginby name means the code obtained at installation time can differ from the code originally reviewed. The instruction to start a fresh chat indicates that the plugin is loaded into subsequent agent sessions and exposes additionalclawlink_*tools.No malicious plugin implementation is present in the audited project, and the audit therefore does not establish that the current package is malicious. The weakness is that this skill delegates security-sensitive behavior to an externally distributed, unpinned component without providing an integrity control.
Attack Path
- An attacker compromises the plugin publisher account, registry entry, distribution infrastructure, or another part of the plugin supply chain.
- The attacker publishes a modified release under the same mutable
clawhub:clawlink-pluginidentifier. - A user follows the documented installation command.
- OpenClaw downloads and installs the modified plugin without validating it against a version or digest specified by this skill.
- The user starts a fresh chat, causing the installed plugin and its tools to become available.
- Malicious plugin code can then act with whatever local access and integration privileges the OpenClaw plugin runtime grants it.
Impact Assessment
A compromised plugin could potentially access local plugin configuration, device credenti ...[truncated 491 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an explicitly reviewed immutable version.
- Where supported, include and verify a cryptographic package digest or signature.
- Link to the exact source revision corresponding to the installed artifact.
- Require signed releases from a verified publisher and document how users can verify the signature.
- Avoid automatic upgrades to unreviewed releases.
- Run the plugin in a restricted sandbox with minimal filesystem, network, process, and credential access.
- Document the plugin's requested permissions before installation.
- Maintain a reviewed lockfile or equivalent installation manifest so future installations resolve to the same artifact.
