T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Handles OAuth Credentials and OneNote Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–49 and line 71
Vulnerability Type: Unpinned privileged third-party dependency
Risk Level: HighComplete Code Snippet
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartThe plugin is subsequently entrusted with OAuth credentials:
text **No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Microsoft Graph request on the user's behalf.Technical Analysis
The skill instructs users to install
clawlink-pluginwithout specifying an immutable version, cryptographic digest, or verifiable publisher signature. It then explicitly allowlists the plugin and restarts the gateway so that the new component is loaded.This dependency occupies a sensitive trust position: according to the skill documentation, ClawLink stores Microsoft OAuth tokens, injects them into Microsoft Graph requests, and proxies requests involving private OneNote content. The audited project contains only
SKILL.md; it does not include the plugin source or a lockfile, signature, checksum, or reproducible build reference. Consequently, the audit cannot verify the plugin's credential storage, network behavior, update process, effective permissions, or correspondence to reviewed source code.The finding is a supply-chain exposure rather than confirmed malicious behavior. The documentation openly identifies ClawLink as an OAuth intermediary, and no direct evidence of credential theft, malware, or hidden exfiltration was found in the artifact.
Attack Path
- An attacker compromises, replaces, or publishes a malicious update to the unpinned
clawlink-plugindistribution. - A user follows the skill instructions and installs whichever package version the registry currently resolves.
- The user adds the plugin to
tools.alsoAllowand restarts the gateway, ...[truncated 1147 chars]
- An attacker compromises, replaces, or publishes a malicious update to the unpinned
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an immutable, reviewed version rather than installing an unconstrained package reference.
- Verify the dependency using a trusted publisher signature and a documented cryptographic digest.
- Publish or reference the exact source revision and reproducible build materials corresponding to the distributed plugin.
- Add a lockfile or equivalent dependency manifest that prevents silent version substitution.
- Document all Microsoft OAuth scopes and justify each scope according to least privilege.
- Separate read-only and write-capable authorization where supported, requesting write access only when necessary.
- Document token encryption, retention, rotation, revocation, and network destinations.
- Restrict the plugin allowlist and tool permissions to the minimum OneNote capabilities required.
- Require explicit user approval before plugin installation, account pairing, and write operations.
- Provide integrity-verification and incident-response instructions, including immediate token revocation and plugin removal.
