T08 · Insecure Dependencies
Warning
- Location
SKILL.md:43- Finding
Unpinned Third-Party Plugin Installation and Global Enablement
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43–50
Vulnerability Type: Unpinned third-party dependency installation and enablement
Risk Level: MediumVulnerable Code
markdown ## Install Install the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat. ```bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restarttext Equivalent enablement and restart commands are repeated in the troubleshooting procedure at `SKILL.md`, lines 273–280. ### Technical Analysis The skill instructs the agent to install `clawlink-plugin` without specifying an immutable version, cryptographic digest, or signature-verification procedure. It then adds the plugin to `tools.alsoAllow` and restarts the OpenClaw gateway so the newly installed component becomes active. Consequently, the code ultimately executed depends on whichever plugin release the external package source serves at installation time. Its behavior may change after this skill has been reviewed. The audited project contains only `SKILL.md`; it does not include the plugin implementation, so the plugin's network activity, credential handling, permission boundaries, and enforcement of user confirmation cannot be verified from the artifact. The documentation also states that ClawLink stores OAuth tokens, proxies Google Meet requests, and can process participant information, recordings, and transcripts. These activities match the declared integration purpose, but they increase the sensitivity of a supply-chain compromise. ### Attack Path 1. An attacker compromises the plugin publisher account, distribution service, release process, or another dependency used by a later plugin release. 2. A user or agent follows the skill's unpinned installation command. 3. The external source supplies the compromised releas ...[truncated 1021 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
clawlink-pluginto a reviewed, immutable version rather than installing the latest package implicitly. - Verify a publisher signature or documented cryptographic digest before enabling the plugin.
- Include the relevant plugin source and permission manifest in the review scope, or provide a reproducible-build reference to the exact audited release.
- Require explicit user approval before each security-sensitive setup step: installation, allowlisting, account pairing, and gateway restart.
- Restrict the plugin to only the Google Meet tools and OAuth scopes required for the requested operation.
- Document the OAuth scopes, token encryption and retention controls, revocation procedure, data-processing boundaries, and incident-response process.
- Isolate third-party plugins from unrelated host resources and credentials.
- Avoid automatically repeating installation or allowlisting commands during troubleshooting without first verifying the installed package's version, integrity, and publisher.
- Pin
