T08 · Insecure Dependencies
- Location
SKILL.md:49- Finding
Unpinned Privileged Third-Party Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 49–53
Vulnerability Type: Unpinned third-party dependency with immediate privileged activation
Risk Level: Mediumbash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The documented installation procedure retrieves
clawlink-pluginfrom ClawHub without specifying an immutable version, commit, or cryptographic digest. The downloaded plugin is then added to OpenClaw's allowed tools and activated by restarting the gateway.Because the package reference is mutable, the code installed by this command can differ from the version originally reviewed. The project provides no checksum, signature-verification procedure, or local plugin source through which the installed implementation can be independently validated. This creates a supply-chain trust boundary in which the security of the integration depends on the registry, publisher account, distribution infrastructure, and latest published plugin release.
The plugin has a sensitive role because it mediates GitHub operations authenticated through a connected OAuth account. Exploitation therefore requires a malicious or compromised plugin release and a user following the documented installation and connection procedure; the Skill file itself does not contain an embedded malicious payload.
Attack Path
- An attacker compromises the plugin publisher account, ClawHub distribution path, or another component capable of replacing the mutable
clawlink-pluginpackage. - The attacker publishes a modified release under the same unversioned package identifier.
- A user follows the instructions in
SKILL.mdand installs the package without an immutable version or digest. - The configuration command explicitly adds the plugin to OpenClaw's allowed tools.
- Restarting the gateway loads an ...[truncated 1094 chars]
- An attacker compromises the plugin publisher account, ClawHub distribution path, or another component capable of replacing the mutable
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a reviewed, immutable version rather than installing a mutable package reference.
- Where supported, pin and verify a cryptographic digest in addition to the version.
- Publish the expected package publisher identity, version, checksum, and signature-verification procedure in
SKILL.md. - Verify package provenance and integrity before adding the plugin to
tools.alsoAllow. - Separate installation from activation: do not allowlist the plugin or restart the gateway until integrity and provenance checks have succeeded.
- Use the minimum GitHub OAuth scopes required for the requested tasks and avoid broad repository or administrative permissions by default.
- Prefer read-only scopes unless the user explicitly enables write functionality.
- Document plugin update controls so later releases require review and explicit approval rather than being adopted implicitly through an unversioned installation.
- Revoke the GitHub connection and remove the plugin immediately if package integrity or publisher ownership cannot be verified.
