T08 · Insecure Dependencies
- Location
SKILL.md:46- Finding
Unpinned Third-Party Plugin Is Installed and Granted Tool Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 46–50
Vulnerability Type: Unpinned and unauditable third-party dependency
Risk Level: MediumVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The Skill instructs the agent to install
clawhub:clawlink-pluginwithout specifying an immutable version, package digest, checksum, or signature verification step. It then explicitly adds the plugin to the allowed-tools configuration and restarts the OpenClaw gateway, causing the newly installed component to be loaded.The plugin source is not included in the audited project, so its implementation and effective permissions cannot be verified from this repository. Because the package reference is mutable, the code installed at execution time may differ from the code originally reviewed. This creates a supply-chain trust gap, particularly because the plugin participates in OpenAI account pairing, credential handling, and API request proxying.
Attack Path
- An attacker compromises the plugin publisher account, package registry, distribution infrastructure, or a mutable future plugin release.
- A user invokes the Skill and approves installation.
- The agent installs the current package resolved by
clawhub:clawlink-plugin, without checking an immutable digest or signature. - The configuration command grants the plugin tool access.
- The gateway restart loads and activates the compromised plugin.
- During pairing or subsequent OpenAI operations, the plugin can potentially intercept credentials, alter requests or responses, invoke accessible tools, or transmit account data within the limits of its runtime privileges.
Impact Assessment
Successful exploitation could provide attacker-controlled plugin code with the privileges assigned to OpenClaw ...[truncated 711 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a specific, audited version and preferably an immutable content digest.
- Verify a publisher signature and package checksum before installation; abort on verification failure.
- Publish the plugin source and reproducible-build instructions so the installed artifact can be independently audited.
- Display the resolved version, digest, publisher identity, requested permissions, and affected configuration before requesting user approval.
- Grant only the minimum tools and permissions required for OpenAI integration rather than broadly allowlisting the plugin.
- Run the plugin in a sandbox with restricted filesystem, network, process, and credential access.
- Scope OpenAI credentials to a dedicated project or service account with minimum privileges, spending limits, and audit logging.
- Add an explicit rollback procedure that disables the plugin, restores the previous configuration, and restarts the gateway safely.
- Continuously monitor the dependency for ownership changes, revoked signatures, reported compromises, and unexpected digest changes.
