T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Installation and Broad Tool Authorization
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:47-49
Vulnerability Type: Unpinned third-party dependency installation and authorization
Risk Level: MediumVulnerable Code:
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartThe same authorization and restart commands are repeated at
SKILL.md:311-312.Technical Analysis
The installation command references
clawhub:clawlink-pluginwithout an immutable version, digest, or checksum. The instructions then add that plugin to the tool allowlist and restart the gateway, causing the downloaded component to be loaded with authorized tool access.Because the audited project does not contain the plugin implementation, a lockfile, a cryptographic digest, or verification steps tied to a specific artifact, reviewers cannot establish that the code installed later will be identical to the code originally assessed. A compromised publisher account, registry, or mutable package release could therefore introduce altered plugin code through the documented installation workflow.
The Skill also states that ClawLink stores the user's OAuth token and injects it into Google Slides requests (
SKILL.md:71). This creates a sensitive external trust boundary and raises the potential impact if the authorized dependency is compromised. The audit found no evidence that the current plugin is malicious or that credentials are presently being misused; the finding concerns the unsafe dependency acquisition and authorization process.Attack Path
- An attacker compromises the plugin publisher account, package registry, release process, or another part of the distribution chain.
- The attacker publishes modified code under the mutable
clawhub:clawlink-pluginreference. - A user follows the Skill instructions and installs that reference without verifying a version-speci ...[truncated 1159 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an audited, immutable version rather than installing a mutable package reference.
- Verify a publisher signature or cryptographic digest before installation and document the expected value in the setup procedure.
- Publish reproducible build information and artifact provenance so users can validate the installed component.
- Grant only the minimum integration-specific tools and permissions needed instead of broadly authorizing the entire plugin where finer controls are available.
- Require explicit user approval before plugin installation, allowlist modification, OAuth connection, and gateway restart.
- Enforce write confirmation independently of the third-party plugin so a compromised dependency cannot bypass confirmation controls.
- Document incident-response steps, including disabling and uninstalling the plugin, removing its allowlist entry, disconnecting ClawLink, revoking Google OAuth access, and reviewing account activity.
- Regularly re-audit pinned releases and monitor the package source for publisher, ownership, signing-key, or provenance changes.
