T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Is Installed and Granted Tool Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–49
Vulnerability Type: Unpinned executable dependency
Risk Level: MediumComplete Code Snippet:
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The documented setup installs
clawlink-pluginwithout pinning an immutable version, commit, digest, or verified signature. It then explicitly adds that plugin to the allowed tool configuration and restarts the gateway, activating the installed package.The reviewed project contains only
SKILL.md; it does not include the plugin implementation or integrity metadata. Consequently, the executable behavior receiving tool access cannot be verified from this artifact. A mutable dependency may change after this skill has been reviewed, creating a supply-chain risk if its distribution account, package, release pipeline, or future version is compromised.The trust impact is increased by the credential-handling role described at
SKILL.md, line 71:text ClawLink stores the API key securely and injects it into every ElevenLabs API request on the user's behalf.This statement does not demonstrate credential misuse. It does, however, establish that the external component occupies a security-sensitive position involving ElevenLabs credentials and authenticated API requests.
Attack Path
- An attacker compromises the plugin publisher, package registry entry, release pipeline, or another distribution component.
- The attacker publishes a malicious release under the unversioned
clawlink-pluginidentifier. - A user follows the installation instructions in
SKILL.md. - OpenClaw resolves and installs the attacker-controlled release because no immutable version or digest is specified.
- The configuration command allowlists the plugin.
- The gateway restart ...[truncated 792 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a reviewed, immutable version rather than installing a mutable package identifier.
- Where supported, verify the package with a cryptographic digest and a trusted publisher signature before installation.
- Provide links to the auditable plugin source, signed release artifacts, and reproducible build or provenance records.
- Separate installation from allowlisting so package identity and integrity can be verified before tool access is granted.
- Document the plugin's exact runtime permissions, network destinations, credential-storage design, and credential-access boundaries.
- Apply least privilege by granting only the tools and account scopes required for ElevenLabs operations.
- Establish dependency update controls, including review and integrity verification before adopting a new plugin release.
- Provide revocation and incident-response instructions for disabling the plugin and rotating ElevenLabs credentials if compromise is suspected.
