T08 · Insecure Dependencies
- Location
SKILL.md:42- Finding
Unpinned Third-Party Plugin Installation and Activation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 42–46
Vulnerability Type: Unpinned and unverifiable third-party dependency
Risk Level: Mediumbash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The installation procedure retrieves
clawlink-pluginfrom an external package registry without specifying an immutable version, cryptographic digest, or verifiable signature. It then explicitly adds the plugin to the OpenClaw tool allowlist and restarts the gateway, causing the retrieved component to become active.Although the documentation describes the plugin as verified, the audited project contains no lockfile, checksum, signature, or plugin source code that would allow its reviewed behavior to be tied to the artifact installed later. Consequently, the effective plugin implementation may change after this Skill has been audited. A registry compromise, publisher-account compromise, or malicious future release could expose users to attacker-controlled plugin behavior.
Attack Path
- An attacker compromises the plugin publisher account, package registry entry, or upstream release process.
- The attacker publishes a modified release under the same mutable
clawhub:clawlink-pluginidentifier. - A user follows the documented installation command, which retrieves the current package without validating a fixed version or digest.
- The subsequent configuration command adds the installed plugin to the OpenClaw tool allowlist.
- The gateway restart loads and activates the compromised plugin.
- The malicious plugin operates with the permissions available to an enabled OpenClaw plugin and may intercept or manipulate integration operations.
Impact Assessment
Successful exploitation could permit attacker-controlled code to execute within the plugin's runtime context. The ...[truncated 626 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an immutable, reviewed version rather than installing from a floating package identifier.
- Require a publisher signature or cryptographic digest and verify it before installation and activation.
- Record the approved version and integrity value in the Skill documentation or a dependency lockfile.
- Separate installation from activation: do not allowlist the plugin or restart the gateway until verification succeeds.
- Document the plugin's exact permissions and reduce them to the minimum necessary for Resend operations.
- Maintain a trusted release process with provenance attestations and periodic dependency review.
- Re-audit the plugin whenever its pinned version or integrity digest changes.
