T08 · Insecure Dependencies
Warning
- Location
SKILL.md:44- Finding
Unpinned Third-Party Plugin Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 44–51
Vulnerability Type: Unpinned executable third-party dependency
Risk Level: Mediummarkdown ## Install Install the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat. ```bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restarttext ### Technical Analysis The Skill instructs the agent to install an executable third-party plugin using a mutable package identifier. It does not pin an audited version, specify a cryptographic digest, require publisher-signature validation, or provide another mechanism for verifying that the installed artifact matches the version reviewed with this Skill. The subsequent configuration command explicitly permits the plugin, and the gateway restart loads it into OpenClaw. This makes the plugin part of the trusted execution boundary. Because the package reference is not immutable, the code retrieved at installation time may differ from the code that existed when the Skill was reviewed. The installation also enables the general `clawlink-plugin` rather than documenting enforcement of a Telegram-only permission boundary. Although the Skill states that the plugin is verified and requires user confirmation before setup, those controls do not independently establish artifact integrity or constrain the plugin's runtime permissions. ### Attack Path 1. An attacker compromises the plugin publisher, its ClawHub account, the package registry, or the plugin's delivery pipeline. 2. The attacker publishes a malicious release under the existing mutable `clawhub:clawlink-plugin` identifier. 3. A user approves setup and the agent executes the documented installation command. 4. OpenClaw retrieves the attacker-controlled release because no immutable version or digest is specified. 5. ...[truncated 1326 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a specific, audited, immutable version rather than installing
clawhub:clawlink-pluginwithout a version constraint. - Publish and verify a cryptographic digest for the exact plugin artifact before installation.
- Require validation of a trusted publisher signature and fail closed if signature or digest verification fails.
- Document the package publisher, source repository, release provenance, and reproducible-build or attestation process.
- Review the plugin version's source code and transitive dependencies before recommending installation.
- Restrict plugin permissions to the minimum required Telegram capabilities. Where supported, allowlist only the necessary Telegram tools instead of the entire integration plugin.
- Clearly present the plugin's runtime permissions, data flows, external endpoints, and credential-handling model before requesting user consent.
- Keep explicit confirmation requirements for installation, gateway restart, and all write operations.
- Provide a removal and rollback procedure that disables the plugin, removes its allowlist entry, and revokes associated ClawLink and Telegram credentials.
- Re-audit and re-pin the artifact whenever upgrading rather than automatically accepting the latest available release.
- Pin the plugin to a specific, audited, immutable version rather than installing
