T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned External Package Installation Prevents Verification of Executed Plugin Code
- Content
View full analysis
| `odoo_create` | Create records on any model | | `odoo_update` | Update existing records | | `odoo_delete` | Delete records | | `odoo_workflow` | Execute model methods (confirm/cancel/post) | ``` ### Technical Analysis The audited artifact contains only `SKILL.md`; it does not include the advertised TypeScript plugin implementation, package manifest, lockfile, integrity metadata, or distributable code. The installation instruction invokes `npx clawhub install openclaw-odoo`, which resolves and installs an external package without specifying an immutable version or integrity hash. Consequently, the code installed when a user follows this instruction may differ from the content available during this audit. Reviewers cannot verify the plugin's effective implementation, transitive dependencies, network destinations, credential handling, or authorization controls. This is a supply-chain trust issue rather than evidence that the currently advertised package is malicious. Exploitation would require compromise or unauthorized replacement of the package, publisher account, registry, name-resolution process, or a future package release. The exposure is security-sensitive because the documentation states that the plugin: - Authenticates to Odoo using an API key. - Automatically loads configuration from `.env ...[truncated 2033 chars]- Remediation
View remediation
