T08 · Insecure Dependencies
- Location
skill.md:114- Finding
Unpinned Third-Party Plugin Installed Globally
- Content
View full analysis
Vulnerability Details
File Location:
skill.md:114
Vulnerability Type: Unpinned third-party dependency and globally scoped installation
Risk Level: MediumVulnerable Code
bash npm install -g @wristclaw/openclawThe same installation method is recommended again in the security guidance at
skill.md:416:text Preferred: npm install -g @wristclaw/openclawTechnical Analysis
The documented command installs the latest version of
@wristclaw/openclawavailable from the configured npm registry rather than an exact, previously audited version. Consequently, the effective code installed when a user follows these instructions can differ from the code that existed when this Skill was reviewed.The installation is also global. This gives the downloaded package access within the npm global installation context and makes the plugin available across OpenClaw sessions. A project lockfile does not pin the resolution performed by this direct global installation command.
This is a supply-chain weakness rather than evidence that the current package is malicious. Exploitation would require compromise of the package, its publisher account, the configured registry, or another relevant distribution mechanism.
Attack Path
- An attacker compromises the npm publisher account, package release process, or package distribution path for
@wristclaw/openclaw. - The attacker publishes a malicious package version or modifies a future release to include malicious installation or runtime behavior.
- A user follows the Skill instructions and runs
npm install -g @wristclaw/openclaw. - npm resolves and downloads the attacker-controlled release because no exact version or independently verified digest is specified.
- Package lifecycle code, if present and permitted, can execute during installation. The installed OpenClaw plugin can subsequently execute when loaded by OpenClaw.
- The malicious com ...[truncated 733 chars]
- An attacker compromises the npm publisher account, package release process, or package distribution path for
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an exact audited version, for example
@wristclaw/openclaw@0.2.0, rather than installing the latest registry release. - Publish and verify a cryptographic digest for the exact package archive before installation. The expected digest should be stored in the reviewed Skill artifact or another authenticated release manifest.
- Avoid global installation where possible. Install the dependency in a dedicated, least-privileged plugin directory with a committed lockfile.
- Disable npm lifecycle scripts during acquisition when they are not required, inspect the unpacked package, and only then perform the controlled installation.
- Run OpenClaw and the plugin under a dedicated non-administrative account with narrowly scoped filesystem and network permissions.
- Include the audited plugin source or a verifiable immutable package reference in the reviewed artifact so that the installed implementation can be assessed together with the Skill instructions.
- Correct the statement that the direct global installation is pinned by package-manager lockfiles, or replace the command with an installation workflow that actually uses a reviewed lockfile.
- Pin the plugin to an exact audited version, for example
