T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Receives Broad OAuth-Backed Financial Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–49 and supporting context at lines 71 and 109
Vulnerability Type: Unpinned third-party dependency with access to sensitive financial operations
Risk Level: HighVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartSupporting credential-access context:
markdown **No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every QuickBooks Online API request on the user's behalf.Supporting authorization context:
markdown - **All write operations require explicit user confirmation.** Before executing any create, update, or delete call, confirm the target resource and intended effect with the user.Technical Analysis
The installation command identifies the plugin only by its mutable marketplace name. It does not specify an immutable version, commit, artifact digest, or signature. The subsequent command explicitly adds that plugin to OpenClaw's allowed tools, and the gateway restart activates it.
The plugin's source is not included in the audited project, so its implementation and handling of credentials cannot be verified from this artifact. The documented design places ClawLink in the OAuth and request path: it stores the QuickBooks OAuth token and proxies authenticated API requests. The tool catalog includes access to sensitive accounting data and write operations involving invoices, payments, bank accounts, bills, journal entries, company settings, and batch operations.
This creates a supply-chain trust boundary. If the named package, publisher account, marketplace distribution channel, or update process is compromised, a modified package could be installed under the same trusted name. Explicit confirmation for writes is a useful application-level control, but it does not independently constrain malicious ...[truncated 1618 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a specific audited version and, where supported, an immutable artifact digest.
- Require package-signature and publisher-provenance verification before installation.
- Publish, vendor, or otherwise make the exact installed plugin source available for independent review.
- Implement lockfiles or an equivalent mechanism so subsequent setup runs cannot silently resolve to a different artifact.
- Request the minimum QuickBooks OAuth scopes needed for the requested task and separate read-only access from write access where possible.
- Restrict the enabled QuickBooks tools to the minimum required subset rather than exposing the complete integration catalog.
- Enforce write confirmation outside the plugin's own trust boundary so a compromised plugin cannot bypass it.
- Maintain detailed audit logs for OAuth grants, plugin updates, API calls, previews, confirmations, and financial writes.
- Provide clear procedures to revoke QuickBooks authorization, invalidate stored tokens, disable the plugin, and investigate suspicious activity.
- Review plugin updates in a staging environment before deployment and alert users whenever package code, requested scopes, or integrity metadata changes.
