T08 · Insecure Dependencies
- Location
references/install.md:3- Finding
Unpinned Third-Party Plugin Installation and Activation
- Content
View full analysis
Vulnerability Details
File Location:
references/install.md, lines 3–8 and 16–21
Vulnerability Type: Unpinned executable third-party dependency
Risk Level: MediumComplete Code Snippet
markdown - Install [KleinClaw](https://clawhub.ai/plugins/kleinclaw), then enable it: ```bash openclaw plugins install clawhub:kleinclaw openclaw plugins enable kleinclaw openclaw gateway restart- The plugin bundles the
miniclawruntime and this helper skill, so no separate executable path is required. The standalonekleinanzeigen-helperskill fromilyaZar/kleinanzeigen-helperis optional guidance only; the callable tools still come from the KleinClaw plugin.
text ### Technical Analysis The installation procedure retrieves `clawhub:kleinclaw` without specifying an immutable version, release digest, checksum, or required signature. It then enables the installed plugin and restarts the gateway, causing its code to be loaded. The documentation states that the plugin bundles the executable `miniclaw` runtime. That runtime is not included in this project, so its implementation and the exact artifact users will receive cannot be verified by auditing this repository alone. Because the package reference is mutable, the effective executable content may differ between installation times even when these reviewed instructions remain unchanged. This is an insecure dependency and supply-chain boundary rather than evidence that the current KleinClaw package is malicious. ### Attack Path 1. An attacker compromises the package registry entry, publisher account, release pipeline, or another distribution component associated with `clawhub:kleinclaw`. 2. The attacker publishes a modified package under the same unversioned identifier. 3. A user follows the documented `openclaw plugins install clawhub:kleinclaw` command. 4. The package m ...[truncated 864 chars]- The plugin bundles the
- Remediation
View remediation
Remediation Suggestions
- Pin KleinClaw to a reviewed, immutable version and, where supported, a cryptographic artifact digest.
- Publish the expected checksum and provide a documented verification command before plugin enablement.
- Require package-signature verification and document the expected publisher identity or signing key.
- Link the pinned release to auditable source code and reproducible build information for the bundled
miniclawruntime. - Separate installation from enablement so users can inspect the resolved package metadata, requested permissions, and integrity results before loading it.
- Apply least privilege to the OpenClaw/plugin process, narrowly scope
adRoots, and restrict filesystem and browser-profile access to only what is required. - Document a controlled upgrade process that reviews release notes, source changes, signatures, and hashes before changing the pinned version.
