T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned Third-Party Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 31–35
Vulnerability Type: Unpinned external dependency
Risk Level: MediumVulnerable Code
markdown **Step 1** — Install the ClawLink plugin:text openclaw plugins install clawhub:clawlink-pluginTechnical Analysis
The skill directs users to install the third-party
clawlink-pluginpackage without specifying an immutable version, integrity hash, or verifiable signature. The plugin's implementation is not included in the audited project, so its behavior cannot be assessed from this package. The command consequently trusts whichever artifact the external registry resolves at installation time.This creates a supply-chain risk: compromise of the package publisher, registry, release process, or package ownership could cause users to install code different from the version originally reviewed. The risk is heightened because the documentation indicates that the plugin participates in account pairing, stores device credentials in local OpenClaw configuration, and brokers access to DataForSEO.
Attack Path
- An attacker compromises the package publisher, registry account, distribution infrastructure, or another component controlling
clawhub:clawlink-plugin. - The attacker publishes a modified malicious release under the same mutable package identifier.
- A user follows the skill's installation command.
- OpenClaw resolves and installs the attacker-controlled release because no version or integrity constraint is supplied.
- The installed plugin executes within the OpenClaw plugin trust boundary.
- Depending on its granted permissions, the malicious plugin could inspect accessible configuration or credentials, alter proxied tool operations, or transmit integration data externally.
Impact Assessment
Successful exploitation could provide execution within the privileges granted to OpenClaw plugins. Potentially exposed assets include locally stored ClawLink de ...[truncated 417 chars]
- An attacker compromises the package publisher, registry account, distribution infrastructure, or another component controlling
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an immutable, security-reviewed version rather than installing the mutable package name alone.
- Publish and verify a cryptographic checksum or trusted signature for the exact plugin artifact.
- Document the authoritative publisher identity and verified source repository.
- Provide reproducible-build instructions or source provenance that maps the reviewed source to the distributed artifact.
- Review the plugin's manifest, requested permissions, credential handling, network destinations, update mechanism, and local storage protections before recommending installation.
- Apply least privilege so the plugin can access only the configuration and integration operations required for DataForSEO.
- Require explicit review and approval before upgrades, particularly when a new release changes permissions or credential-handling behavior.
