T08 · Insecure Dependencies
- Location
SKILL.md:84- Finding
Unpinned Third-Party Plugin Installation Enables Supply-Chain Code Execution
- Content
View full analysis
- Remediation
View remediation
``` Use equivalent explicit version pinning for ClawHub packages if supported. 2. Pin an immutable artifact digest or cryptographic checksum in addition to the version. Verify it before installation so that a registry cannot silently replace an artifact associated with the same version. 3. Require package or release signature verification where supported. Document the expected publisher identity, signing key, repository, and verification procedure. 4. Remove `@latest` from installation documentation. Upgrades should be deliberate and should occur only after reviewing the release source, changelog, dependency changes, and artifact integrity. 5. Avoid `--force` in the default installation path. Reserve it for an explicitly diagnosed repair procedure, warn that it replaces an existing installation, and require operator confirmation. 6. Separate installation from activation. After downloading the pinned package, inspect and verify it before running: ```sh openclaw plugins enable gc-provider openclaw gateway restart ``` 7. Run OpenClaw under a dedicated least-privileged account. Restrict filesystem access, outbound network access, environment variables, and credential availability to reduce the impact of a compromised plugin. 8. Establish a controlled update policy that records the approved version and digest and requires security review before changing either value. ]]>
