T08 · Insecure Dependencies
- Location
SKILL.md:54- Finding
Unpinned Privileged Third-Party Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 54–58
Vulnerability Type: Supply-chain risk from an unpinned third-party plugin
Risk Level: MediumVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The setup procedure installs
clawlink-pluginfrom an external package source without specifying an immutable version, content digest, checksum, or verifiable signature. It then explicitly allowlists the plugin and restarts the OpenClaw gateway, causing externally supplied executable code to become active.The repository contains only
SKILL.md; it does not include the plugin source, a lock file, a cryptographic integrity manifest, or other evidence that would permit review of the installed artifact. Although the document calls the plugin “verified,” that assertion cannot be independently established from the audited project.This creates a supply-chain risk because the effective plugin artifact may change after this skill has been reviewed. Compromise of the package publisher, registry, distribution channel, or mutable package release could result in users installing behavior different from the behavior represented by this document.
Attack Path
- An attacker compromises the plugin publisher account, package registry entry, distribution infrastructure, or another component of the plugin supply chain.
- The attacker replaces or updates the mutable
clawlink-pluginartifact with a malicious release. - A user follows the documented installation command, which retrieves the current external artifact without validating an immutable version or digest.
- The next command adds the plugin to
tools.alsoAllow, granting it access through OpenClaw’s tool configuration. - The gateway restart loads and activates the compromised plugin.
- The malicious ...[truncated 1069 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an immutable, reviewed version rather than installing a mutable package name.
- Require a cryptographic digest or checksum and verify it before installation.
- Require signed releases and validate the signature against a documented trusted publisher key.
- Publish or reference the exact plugin source corresponding to the pinned artifact so its behavior can be independently audited.
- Add a lock file or integrity manifest containing the expected version, digest, source repository, and build provenance.
- Review and document the plugin’s required permissions before adding it to
tools.alsoAllow. - Apply least privilege by exposing only the tools and integrations necessary for Google Ads operations.
- Isolate the plugin in a restricted runtime with limited filesystem, network, process, and credential access.
- Separate installation, allowlisting, and gateway activation into explicit steps so integrity and permission checks occur before activation.
- Establish a controlled update process in which each new plugin artifact is reviewed and its digest approved before deployment.
