T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Is Installed and Granted Tool Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:47-49andSKILL.md:268-269
Vulnerability Type: Unpinned privileged third-party dependency
Risk Level: HighVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartThe configuration and restart instructions are repeated in the troubleshooting workflow:
bash openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The Skill directs users to install
clawhub:clawlink-pluginwithout specifying an immutable version, package digest, signature, or verified source revision. It then adds the plugin to the OpenClaw tool allowlist and restarts the gateway, causing the downloaded component to become active.Because the effective plugin implementation is not present in the audited project, its behavior cannot be verified from
SKILL.md. An unpinned registry dependency can change after this Skill has been reviewed. If the registry account, distribution infrastructure, or package itself is compromised, later installations could receive attacker-controlled code while retaining the same trusted package name.The explicit allowlisting operation increases the consequence of dependency compromise because the installed plugin is authorized to expose and invoke tools in subsequent OpenClaw sessions.
Attack Path
- An attacker compromises the plugin publisher account, package registry, or distribution path for
clawhub:clawlink-plugin. - The attacker publishes a modified plugin under the same unversioned package identifier.
- A user follows the instructions in
SKILL.mdand installs the latest package associated with that identifier. - The user adds the plugin to
tools.alsoAllow. - The gateway is restarted and loads the attacker-controlled plugin.
- The malic ...[truncated 762 chars]
- An attacker compromises the plugin publisher account, package registry, or distribution path for
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a reviewed, immutable version rather than installing an unrestricted current release.
- Verify the package using a cryptographic digest and publisher signature before installation.
- Publish or link to the exact source revision corresponding to the pinned artifact so its behavior can be independently audited.
- Use a trusted registry with package provenance, transparency logs, and protected publisher credentials.
- Restrict the plugin allowlist and runtime permissions to only the Google Tasks operations required by the Skill.
- Require explicit user approval before installing the plugin, changing the allowlist, or restarting the gateway.
- Run the plugin in a sandbox with limited filesystem, network, process, and credential access.
- Define a controlled update process in which each new plugin release is reviewed before the pinned version is changed.
