T08 · Insecure Dependencies
- Location
SKILL.md:41- Finding
Unpinned Third-Party Plugin Installed with Credential-Bearing Integration Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 41–47 and 70–79
Vulnerability Type: Unpinned third-party dependency with privileged integration access
Risk Level: MediumVulnerable Code
markdown ## Install Install the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat. ```bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restarttext The same file describes the plugin's credential-bearing role: ```markdown ## Authentication All Motion tool calls are authenticated automatically by ClawLink using the user's connected Motion account. **No API key is required in chat.** ClawLink stores the API key securely and injects it into every Motion API request on the user's behalf.Technical Analysis
The skill instructs the agent to install
clawhub:clawlink-pluginwithout specifying an immutable version, package digest, signature, or other integrity constraint. It then modifies the OpenClaw allowlist and restarts the gateway, activating the newly acquired component.The project contains only
SKILL.md; consequently, the plugin implementation that handles credentials and authenticated requests is outside the reviewed artifact. Although the documentation calls the plugin “verified,” it provides no locally verifiable checksum, signature, immutable release reference, or source snapshot. A mutable package release or compromised distribution account could therefore cause users to install code different from the code originally reviewed.This risk is amplified because the plugin acts as an authenticated intermediary. According to the skill, ClawLink stores the Motion API key and injects it into Motion API requests. The documented tool catalog includes access to workspace, project, task, user, schedule, comment, and custom-field data, as well as ...[truncated 1683 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an immutable, audited version rather than installing a mutable package identifier.
- Require verification of a cryptographic digest or publisher signature before installation and activation.
- Publish or vendor the exact plugin source corresponding to the pinned release so its behavior can be audited alongside the skill.
- Separate installation, allowlisting, and gateway restart into distinct user-approved steps, showing the exact version and integrity metadata before activation.
- Document the exact Motion authorization scopes requested and apply least privilege, excluding destructive capabilities unless explicitly required.
- Isolate the plugin with restricted filesystem, network, process, and secret access appropriate to its function.
- Use short-lived credentials where supported, with secure storage, rotation, revocation, and audit logging.
- Enforce write and destructive-operation confirmation outside the plugin itself so a compromised dependency cannot bypass confirmation policy.
- Maintain an approved-version policy and monitor the dependency for publisher changes, revoked signatures, and unexpected release updates.
