T08 · Insecure Dependencies
- Location
SKILL.md:54- Finding
Unpinned Privileged Third-Party Integration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 54–62
Vulnerability Type: Unpinned third-party plugin with access to credentials and Freshdesk operations
Risk Level: MediumVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartThe associated credential delegation is documented at lines 77–79:
text All Freshdesk tool calls are authenticated automatically by ClawLink using the user's connected Freshdesk account. No API key is required in chat. ClawLink stores credentials securely and injects them into every Freshdesk API request on the user's behalf.Technical Analysis
The installation command identifies
clawlink-pluginwithout an immutable version, release digest, checksum, or signature requirement. The subsequent configuration command explicitly allows the plugin's tools, and the gateway restart loads the installed component.The plugin implementation is not included in the audited project, so its behavior and security controls cannot be independently verified from this artifact. According to the skill documentation, ClawLink stores or mediates Freshdesk credentials and injects them into API requests. This creates a supply-chain trust boundary in which a mutable external dependency receives access to sensitive customer-support data and write-capable Freshdesk operations.
This is an insecure dependency risk rather than evidence that the current plugin is malicious. Exploitation requires the plugin distribution source, an upstream release, or the installation channel to be compromised or otherwise serve an unsafe version.
Attack Path
- An attacker compromises the plugin publisher, package registry entry, distribution channel, or a future unpinned plugin release.
- A user follows the documented installation command, which resolves the mutable `clawhub ...[truncated 1281 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a specific immutable version and, where supported, a cryptographic content digest.
- Require package signature and checksum verification before installation.
- Publish the plugin source and reproducible build instructions so the installed artifact can be independently audited.
- Use a trusted registry namespace with publisher verification and release-provenance attestations.
- Restrict plugin permissions and Freshdesk API scopes to the minimum required for the requested operation.
- Separate read-only and write-capable authorization, granting write access only when necessary.
- Require explicit user approval before plugin installation, allowlisting, gateway restart, account pairing, and scope changes.
- Document credential storage, encryption, retention, revocation, logging, and incident-response controls for the hosted proxy.
- Provide rapid token revocation and plugin rollback mechanisms for compromised releases.
- Retain the documented preview and confirmation workflow for all write operations, while enforcing equivalent authorization controls in the plugin and server-side proxy rather than relying solely on skill instructions.
