T09 · Insecure Skill Coding Practices
- Location
scripts/agents/openclaw.sh:20- Finding
OpenClaw dependency installation occurs before mandatory authorization
- Content
View full analysis
Vulnerability Details
File Location:
scripts/agents/openclaw.sh:20-80, 120
Vulnerability Type: Authorization-order flaw allowing premature remote package execution
Risk Level: MediumTechnical Analysis
The OpenClaw integration downloads and installs the unpinned
latestrelease of@openviking/openclaw-pluginbefore invoking the mandatory confirmation gate:bash # Install plugin source — npm first, fall back to GitHub download local _ov_npm_ok=0 if [[ "${DRY_RUN:-false}" != "true" ]]; then local _npm_reg; _npm_reg=$(ov_first_npm_registry) log_info "Trying npm install @openviking/openclaw-plugin (online, $_npm_reg)..." mkdir -p /tmp/openviking local _npm_stage; _npm_stage=$(mktemp -d /tmp/openviking/ov-npm.XXXXXX) || { log_warn "mktemp failed, falling back to GitHub"; _npm_stage=""; } cat > "$_npm_stage/package.json" << 'OVPKGEOF' { "dependencies": { "@openviking/openclaw-plugin": "latest" } } OVPKGEOF if [[ -n "$_npm_stage" ]] && \ (cd "$_npm_stage" && "$OV_NPM" install \ --registry="$_npm_reg" --no-audit --no-fund 2>&1 | tail -5) && \ [[ -d "$_npm_stage/node_modules/@openviking/openclaw-plugin" ]]; then rm -rf "$ov_runtime_src" cp -a "$_npm_stage/node_modules/@openviking/openclaw-plugin" "$ov_runtime_src" log_ok "openclaw-plugin installed from npm (online) -> $ov_runtime_src" touch "$ov_runtime_src" _ov_npm_ok=1 else log_warn "npm install failed — falling back to GitHub source download" fi [[ -n "$_npm_stage" ]] && rm -rf "$_npm_stage" fi ... if [[ "${DRY_RUN:-false}" != "true" && -d "$ov_runtime_src" ]]; then log_info "Pre-building openclaw-plugin (npm install for runtime deps) for fast runtime recovery..." local _pb_stage; _pb_stage=$(mktemp -d /tmp/openviking/ov-prebuild.XXXXXX) || _pb_stage="" if [[ -n "$_pb_stage" ]]; then cp -a "$ov_runtime_src/." "$_pb_stage/" l ...[truncated 3343 chars]- Remediation
View remediation
Remediation Suggestions
- Move
require_confirmationto the beginning ofagent_openclaw_integrate, before all package provisioning, network requests, cache deletion, npm execution, and persistent writes. - Permit only read-only prerequisite and status checks before confirmation.
- Ensure refusal leaves the filesystem and dependency state unchanged.
- Pin
@openviking/openclaw-pluginto an explicit reviewed version instead oflatest. - Use a lockfile and verified integrity value for the npm installation path, or provision all plugin files through the existing Git-tree blob verification mechanism.
- Consider installing with
--ignore-scriptswhere lifecycle scripts are unnecessary, then perform any required build step through a separately reviewed command. - Add a regression test that invokes the integration, refuses confirmation, and verifies that no network installation occurred and that both persistent runtime directories remain unchanged.
- Move
