T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Is Granted Tool Access and Postmark Credentials
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–49 and 71–77
Vulnerability Type: Unpinned privileged third-party dependency
Risk Level: MediumVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartmarkdown **No API key is required in chat.** ClawLink stores the API key securely and injects it into every Postmark API request on the user's behalf. ### Getting Connected 1. Install the ClawLink plugin (see Install above). 2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet. 3. Open https://claw-link.dev/dashboard?add=postmark and connect Postmark.Technical Analysis
The setup installs
clawlink-pluginwithout specifying an immutable version, package digest, or other locally verifiable integrity constraint. It then explicitly adds that plugin to OpenClaw's tool allowlist and restarts the gateway, activating the installed component.The integration is subsequently entrusted with the user's Postmark API key and acts as a proxy for credential-backed Postmark operations. The audited project contains only
SKILL.md; it does not include the plugin source, a dependency lockfile, a checksum, or signed provenance data. Consequently, the exact code installed at setup time cannot be verified from this artifact and could change independently after the Skill has been reviewed.This creates a supply-chain trust boundary: compromise or unauthorized replacement of the package, its distribution account, or its delivery infrastructure could cause users to install attacker-controlled code with permitted tool access. The documented preview and confirmation workflow can govern compliant tool use, but it cannot constrain malicious behavior inside the trusted plugin itself.
Attack Path
- An attacker compromises or replaces the unpinned
clawlink-pluginpackage or its distribution channel. ...[truncated 1479 chars]
- An attacker compromises or replaces the unpinned
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an immutable, reviewed version rather than installing an unconstrained package name.
- Verify the package with a cryptographic digest or trusted signature before installation.
- Document the expected publisher identity, release version, checksum, and provenance.
- Require explicit reapproval whenever the plugin version, digest, publisher, or requested permissions change.
- Review or vendor the exact plugin source distributed with the Skill so its behavior can be audited alongside
SKILL.md. - Restrict OpenClaw tool permissions and Postmark API scopes to the minimum capabilities required.
- Prefer short-lived, revocable, narrowly scoped authorization over a reusable server API key where supported.
- Provide a documented removal and credential-revocation procedure for suspected compromise.
- Keep write-operation preview and confirmation controls, but enforce them in a trusted host boundary rather than relying solely on the plugin to comply.
