T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Installation and Allowlisting
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–49
Vulnerability Type: Unpinned external dependency installed from a mutable package registry
Risk Level: Mediumbash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartThe same allowlisting and restart instructions are repeated at
SKILL.md, lines 318–319:bash openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The skill instructs users to install
clawhub:clawlink-pluginwithout specifying an immutable version, digest, or integrity hash. It then adds the plugin to OpenClaw's tool allowlist and restarts the gateway, causing the newly installed component to become active.The plugin implementation is not included in the audited project, which contains only
SKILL.md. Consequently, the plugin's behavior, dependency tree, requested privileges, and handling of OAuth-backed Google Docs data cannot be verified from this artifact. The skill describes the package as “verified,” but no signature, checksum, immutable source reference, or other verification evidence is present in the repository.This is a supply-chain trust weakness rather than evidence that the current package is malicious. Exploitation requires compromise or malicious replacement of the external package or its distribution channel.
Attack Path
- An attacker compromises the external package publisher, registry entry, release process, or a dependency used by
clawlink-plugin. - The mutable package identifier resolves to an attacker-controlled or compromised release.
- A user follows the documented command and installs that release without version or integrity verification.
- The user adds the plugin to
tools.alsoAllow. - The gateway restart activates the compromised plugin.
- The plugin may receive legitimate tool calls and interact ...[truncated 1012 chars]
- An attacker compromises the external package publisher, registry entry, release process, or a dependency used by
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an immutable, reviewed version rather than installing a floating package identifier.
- Require verification using a cryptographic digest or trusted package signature before installation.
- Publish or vendor the corresponding plugin source and lockfile so its behavior and transitive dependencies can be audited.
- Record the expected publisher identity, package version, checksum, and verification procedure directly in the installation instructions.
- Use reproducible builds and a trusted release pipeline with protected signing keys and multi-party release approval.
- Apply least privilege to the plugin allowlist and grant only the Google OAuth scopes necessary for the requested operation.
- Separate read and write capabilities where supported, keeping write tools disabled until explicitly needed.
- Review plugin updates before deployment instead of automatically accepting mutable upstream releases.
- Revoke the integration's OAuth authorization and remove the plugin from the allowlist if package integrity cannot be established.
- Document how administrators can inspect the installed version and verify its integrity before restarting the gateway.
