T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Privileged Third-Party Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47-49
Vulnerability Type: Supply-chain risk caused by an unpinned third-party dependency
Risk Level: MediumVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartThe allowlisting and restart instructions are also repeated at
SKILL.md:275-276:bash openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The installation command references
clawhub:clawlink-pluginwithout specifying an immutable version, integrity digest, or signature-verification requirement. It then adds the installed plugin to the permitted tool list and restarts the gateway, causing the downloaded component to be loaded with integration access.Because the dependency is mutable, the installed implementation may differ from the version that was previously reviewed. If the registry entry, publisher account, release pipeline, or package-distribution infrastructure is compromised, a malicious release could be delivered through the documented installation workflow. The audit found no evidence that the current plugin is malicious; the vulnerability is the absence of controls ensuring that users receive a specific audited artifact.
Attack Path
- An attacker compromises the plugin publisher account, package registry entry, or associated release pipeline.
- The attacker publishes a malicious build under the existing
clawlink-pluginpackage name. - A user follows the skill instructions and installs the package without an immutable version or integrity check.
- The instructions explicitly allowlist the plugin through
tools.alsoAllow. - The gateway restart loads the attacker-controlled plugin.
- The malicious plugin can abuse the integration context or expose deceptive too ...[truncated 839 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a specific, audited version rather than installing a mutable package reference.
- Require verification against a publisher signature and a documented cryptographic digest before installation.
- Publish the authoritative package identity, source repository, release provenance, and expected signing key.
- Use reproducible builds or signed provenance attestations so users can verify that registry artifacts match reviewed source code.
- Separate installation, allowlisting, and gateway restart into distinct steps requiring explicit user approval.
- Apply least privilege to the plugin's tool and network access, and restrict it to only the Facebook capabilities required by the user.
- Review and pin upgrades before deployment instead of automatically accepting mutable releases.
- Document an incident-response procedure for revoking plugin access and connected OAuth credentials if package compromise is detected.
