T08 · Insecure Dependencies
- Location
SKILL.md:48- Finding
Unpinned Third-Party Plugin Installation and Activation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 48-52
Vulnerability Type: Unpinned and unverifiable third-party dependency installation
Risk Level: HighVulnerable Code:
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The skill instructs users to install
clawlink-pluginfrom a third-party package registry without pinning an immutable version, package digest, source revision, or verified signature. It then adds that plugin to the OpenClaw tool allowlist and restarts the gateway, causing the downloaded code to be activated.The plugin implementation is not included in the audited project, which contains only
SKILL.md. Consequently, its runtime behavior, dependency chain, credential handling, and update behavior cannot be verified from the available artifact. A mutable package reference allows the code installed in the future to differ from the code that may have been reviewed when the skill was published.Attack Path
- An attacker compromises the plugin publisher account, package registry, distribution infrastructure, or an unpinned transitive dependency.
- The attacker publishes a malicious version under the existing
clawlink-pluginpackage identifier. - A user follows the skill instructions and installs the package through the mutable
clawhub:clawlink-pluginreference. - The configuration command explicitly allowlists the plugin.
- The gateway restart loads and activates the compromised plugin.
- Malicious plugin code can act within the permissions granted to OpenClaw plugins, potentially intercepting tool calls, accessing integration data, or performing unauthorized operations.
Impact Assessment
Successful exploitation could provide execution within the OpenClaw plugin environment. The practical scope depends on the plugin sandbox an ...[truncated 399 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an immutable, reviewed version rather than installing a floating package reference.
- Verify a cryptographic digest or publisher signature before installation and fail closed if verification fails.
- Publish the plugin source and reproducible build instructions so the installed artifact can be matched to audited source code.
- Document all transitive dependencies and lock them to reviewed versions with integrity hashes.
- Require explicit user approval that clearly identifies the plugin publisher, version, requested permissions, and affected integrations before installation.
- Apply least-privilege restrictions to the plugin and prevent access to unrelated tools, credentials, files, and integrations.
- Avoid automatically restarting the gateway immediately after installation. Perform integrity and permission checks before activation.
- Establish controlled update behavior so later package releases are not installed or activated without a new review and user authorization.
