T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Privileged External Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–49; repeated at lines 455–456
Vulnerability Type: Unpinned third-party dependency with privileged tool access
Risk Level: Mediumbash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartThe equivalent configuration and restart commands are repeated in the troubleshooting instructions:
bash openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The skill instructs users to install
clawlink-pluginfrom an external package registry without specifying an immutable version, content digest, or signature-verification procedure. It then adds the plugin to the tool allowlist and restarts the OpenClaw gateway, causing the externally supplied implementation to become active.The audited project contains only
SKILL.md; it does not include the plugin source, lock metadata, checksums, or reproducible build information. Consequently, the behavior of the installed component—including its treatment of OAuth tokens, proxied HubSpot requests, and CRM data—cannot be statically verified from this package.This creates a supply-chain exposure: the artifact installed in the future may differ from the artifact that was reviewed. Exploitation would require compromise, replacement, or malicious publication of the referenced plugin package or its distribution infrastructure.
Attack Path
- An attacker compromises the plugin publisher account, package registry, build pipeline, or distribution artifact.
- The attacker publishes a modified release under the referenced unversioned package name.
- A user follows the skill instructions and installs the current package using:
openclaw plugins install clawhub:clawlink-plugin. - The user explicitly enables the plugin through
tools.alsoAllow. - The gateway restarts and loads the ...[truncated 1019 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an immutable, reviewed version and preferably a cryptographic content digest.
- Document and enforce package-signature or checksum verification before installation.
- Provide a verifiable source repository, release provenance, and reproducible build information for the plugin.
- Maintain a dependency lock or equivalent integrity metadata in the skill package.
- Require explicit user approval before plugin installation, allowlist modification, and gateway restart.
- Apply least privilege to the plugin and connected HubSpot account, limiting OAuth scopes to the features actually required.
- Separate read-only and write-capable permissions where supported.
- Record and monitor plugin installation, upgrades, OAuth access, and CRM write operations.
- Review new plugin releases before updating rather than automatically resolving an unversioned package to the latest artifact.
