T08 · Insecure Dependencies
- Location
SKILL.md:42- Finding
Unpinned Privileged Third-Party Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 42–47; related credential-handling statement at lines 67–69
Vulnerability Type: Unpinned third-party dependency with access to OAuth-backed Notion operations
Risk Level: MediumVulnerable Code
markdown Install the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat. ```bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restarttext Related credential-handling behavior: ```markdown **No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Notion API request on the user's behalf.Technical Analysis
The skill directs the agent to install
clawhub:clawlink-pluginwithout specifying an immutable version, cryptographic digest, or other integrity constraint. It then adds the plugin to the tool allowlist and restarts the OpenClaw gateway.The plugin is trusted to participate in authenticated Notion operations and, according to the documentation, ClawLink stores and injects the user's OAuth token. However, the plugin implementation is not included in the audited project, which contains only
SKILL.md. Its implementation, credential controls, and network behavior therefore cannot be independently verified by this audit.Installing a mutable package identifier creates a supply-chain risk: the package resolved during installation may differ from the version originally reviewed. If the package publisher, distribution account, registry, or release pipeline were compromised, a malicious release could execute with the plugin's granted capabilities after being explicitly allowlisted.
No evidence in the audited file proves that the current ClawLink plugin is malicious. The finding concerns the unsafe, unpinned insta ...[truncated 1739 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a specific, reviewed version rather than installing a mutable package identifier.
- Verify the package with a publisher signature, cryptographic checksum, or equivalent integrity mechanism before installation.
- Record the expected package source, version, digest, publisher identity, and verification procedure in the skill documentation.
- Require explicit user approval before installation, allowlist modification, gateway restart, account pairing, and any expansion of OAuth scopes.
- Apply least privilege to the Notion integration by requesting only the scopes required for the requested operation and sharing only necessary workspace resources.
- Document ClawLink's token storage, encryption, retention, revocation, logging, and request-proxy behavior so users can make an informed authorization decision.
- Isolate the plugin with restricted filesystem, process, and outbound-network permissions where the OpenClaw runtime supports sandboxing.
- Revalidate the plugin version and integrity before gateway restarts or upgrades, and provide a documented rollback and token-revocation process.
- Prefer independently auditable or bundled integration code when practical, while continuing to avoid embedding OAuth secrets directly in the skill.
