T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Unpinned Third-Party Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:29-33
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: MediumVulnerable Code:
text **Step 1** — Install the ClawLink plugin:text openclaw plugins install clawhub:clawlink-plugintext Start a fresh chat after installing.Technical Analysis
The documented installation command does not specify a fixed version or immutable integrity digest for
clawhub:clawlink-plugin. Consequently, the plugin installed by a user can differ from the version that existed when this Skill was reviewed. Starting a fresh chat then loads the installed plugin and exposes its tools to the agent environment.This creates a supply-chain trust gap: compromise of the package registry entry, publisher account, distribution infrastructure, or a future plugin release could cause users to install executable logic that was not covered by this audit. The reviewed file does not establish that the current plugin is malicious; the vulnerability is the use of a mutable, unverified dependency.
Attack Path
- An attacker compromises the plugin publisher account, registry entry, or release infrastructure, or otherwise causes a malicious future release to be distributed under
clawhub:clawlink-plugin. - A user follows the Skill instructions and runs the unpinned installation command.
- The package manager retrieves the attacker-controlled version because no reviewed version or digest is specified.
- The user starts a fresh chat as instructed, causing the plugin and its tools to be loaded.
- The compromised plugin executes within the permissions available to the OpenClaw plugin environment.
- Depending on granted access, it could misuse local plugin configuration, ClawLink device credentials, integration requests, or Dynamics 365 operations.
Impact Assessment
Successful exploitation could provide access to the privilege ...[truncated 511 chars]
- An attacker compromises the plugin publisher account, registry entry, or release infrastructure, or otherwise causes a malicious future release to be distributed under
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a specifically reviewed version instead of installing a mutable latest release.
- Where supported, pin an immutable cryptographic digest in addition to the version.
- Document the verified publisher identity and authoritative package source.
- Require signature and checksum verification before installation.
- Audit the exact pinned plugin package together with this Skill, including its installation hooks, network destinations, credential handling, and local permissions.
- Apply least privilege to the plugin and connected Dynamics 365 account, limiting CRM roles to operations required by the user.
- Establish a controlled update process in which new plugin releases are reviewed and approved before the pinned version is changed.
- Provide revocation and incident-response guidance for ClawLink device credentials and Dynamics 365 OAuth authorization if dependency compromise is suspected.
