T08 · Insecure Dependencies
- Location
SKILL.md:52- Finding
Unpinned Third-Party Plugin Is Installed and Granted Tool Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 52–56
Vulnerability Type: Unpinned external dependency installed from a mutable package source
Risk Level: HighVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The installation procedure retrieves
clawlink-pluginfrom an external package registry using a mutable package identifier. It does not specify an audited version, immutable digest, signature, or checksum. The plugin's implementation is not included in the audited project, so its behavior cannot be verified from the available source.The subsequent command adds the plugin to the OpenClaw tool allowlist, and restarting the gateway activates the installed component. This creates a supply-chain trust boundary in which externally controlled code is installed and authorized to operate as a tool provider.
Although the skill states that ClawLink stores credentials securely and proxies Freshservice requests, those guarantees cannot be validated without the plugin and service implementation. The finding does not establish that the current plugin is malicious; it establishes that the documented installation process does not cryptographically bind installation to the version reviewed or expected.
Attack Path
- An attacker compromises the external package registry, publisher account, distribution channel, or a later release associated with
clawhub:clawlink-plugin. - The attacker publishes a modified plugin under the same mutable package identifier.
- A user follows the instructions in
SKILL.mdand installs the plugin without a version or integrity constraint. - The user adds the plugin to
tools.alsoAllow. - The gateway restart loads and activates the attacker-controlled plugin.
- The plugin can then abuse the permissions and data exposed through its tool-provider role, inc ...[truncated 934 chars]
- An attacker compromises the external package registry, publisher account, distribution channel, or a later release associated with
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a specific, audited version rather than using an unqualified mutable package name.
- Require an immutable content digest or cryptographic checksum and verify it before installation.
- Require package-signature verification against a trusted publisher key.
- Publish or bundle the exact plugin source so its behavior can be independently reviewed.
- Maintain a lockfile or equivalent integrity manifest recording the approved version and digest.
- Restrict the plugin's tool and host permissions according to least privilege.
- Isolate the plugin in a sandbox that limits filesystem, network, process, credential, and configuration access.
- Document the precise data and credentials available to the plugin and the external ClawLink service.
- Avoid automatically activating newly retrieved code; require explicit verification before allowlisting and gateway restart.
- Establish a controlled update process that audits each new release before changing the pinned version.
