T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unverified Third-Party Plugin Installation and Activation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20–22 and 29–31
Vulnerability Type: T08: Insecure Dependencies
Risk Level: MediumThe documented setup procedures install a third-party plugin through the OpenClaw plugin registry and activate it by restarting the gateway.
bash openclaw plugins install manifest@5.28.5 openclaw config set plugins.entries.manifest.config.mode local openclaw gateway restartbash openclaw plugins install manifest@5.28.5 openclaw config set plugins.entries.manifest.config.apiKey "mnfst_YOUR_KEY" openclaw gateway restartTechnical Analysis
The audited project contains only documentation and publication metadata; it does not include the source code of the installed
manifest@5.28.5plugin, an artifact checksum, or a signature-verification procedure. Consequently, the executable component activated by these instructions cannot be verified from the audited package.Pinning the dependency to version
5.28.5reduces exposure to unintended upgrades, but it does not independently authenticate the downloaded artifact. Security still depends on the integrity of the plugin registry, the publisher account, the distribution infrastructure, and the referenced release.The plugin is described as routing every LLM request and collecting usage information. This places the installed dependency in a sensitive request-processing position. If the distributed artifact were compromised or substituted, malicious code could execute when the OpenClaw gateway loads the plugin.
Attack Path
- An attacker compromises the plugin publisher account, registry, distribution infrastructure, or the published
manifest@5.28.5artifact. - A user follows the instructions in
SKILL.mdand runsopenclaw plugins install manifest@5.28.5. - OpenClaw retrieves and installs the compromised dependency without any documented checksum or signature verification.
- The user restarts the gateway as instructed.
- The compromi ...[truncated 1063 chars]
- An attacker compromises the plugin publisher account, registry, distribution infrastructure, or the published
- Remediation
View remediation
Remediation Suggestions
- Include the reviewed plugin source code in the auditable package, or link to an immutable source revision corresponding exactly to version
5.28.5. - Publish a cryptographic checksum or signed provenance statement for the plugin artifact and add explicit verification steps before installation.
- Use a trusted, authenticated package registry and enforce signature verification in the OpenClaw installation process where supported.
- Generate and retain a software bill of materials for the plugin and its transitive dependencies.
- Run the plugin with least privilege, restricting filesystem access, outbound network destinations, environment variables, and access to unrelated credentials.
- Clearly document which request fields and telemetry are transmitted in cloud mode, including destinations, retention periods, redaction behavior, and deletion controls.
- Store the API key using OpenClaw's protected secret mechanism rather than exposing it through command history or plaintext configuration, where supported.
- Review and verify the downloaded artifact before restarting the gateway, and establish a rollback procedure for compromised releases.
- Include the reviewed plugin source code in the auditable package, or link to an immutable source revision corresponding exactly to version
