T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Unpinned Third-Party Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 18-22
Vulnerability Type: Unpinned executable dependency
Risk Level: Mediumbash # Install the plugin openclaw plugins install @openguardrails/moltguardTechnical Analysis
The Skill directs OpenClaw to download and install a third-party plugin without specifying an exact version or integrity digest. Consequently, the installed code is determined by the package registry at installation time rather than by the content reviewed in this audit.
The package contains only documentation and metadata, so the executable plugin implementation is not available for inspection. The version information is also inconsistent: the
SKILL.mdheader declares version1.0.0, while_meta.jsondeclares version6.8.16. This inconsistency further weakens traceability between the reviewed Skill and the executable dependency.This is a supply-chain risk rather than evidence that the named dependency is currently malicious. A compromised publisher account, registry, package release, or dependency resolution process could replace the effective implementation after this Skill has been reviewed.
Attack Path
- An attacker compromises the package publisher, registry account, or release pipeline for
@openguardrails/moltguard. - The attacker publishes a modified release under the same package name or changes the version resolved by the unpinned installation command.
- A user or agent follows the Skill instructions and executes the installation command.
- OpenClaw downloads and installs the attacker-controlled release.
- The plugin executes with the filesystem, network, credential, and process privileges available to the OpenClaw plugin runtime.
Impact Assessment
Successful exploitation could permit arbitrary code execution within the OpenClaw process context. The resulting scope depends on the plugin sandbox and operating-system account, but could in ...[truncated 248 chars]
- An attacker compromises the package publisher, registry account, or release pipeline for
- Remediation
View remediation
Remediation Suggestions
- Pin installation to a specific, reviewed plugin version rather than resolving the latest release.
- Verify the downloaded artifact using a cryptographic integrity hash or signed provenance.
- Reconcile the version declared in
SKILL.mdwith the version in_meta.json. - Require explicit user confirmation before downloading, installing, or updating executable plugins.
- Review the plugin source and transitive dependencies for the exact pinned release.
- Run the plugin in a restricted sandbox with only the filesystem and network permissions required for detection.
- Configure updates to fail closed if signature, provenance, or integrity verification fails.
