T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Installation and Authorization
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–49
Vulnerability Type: Unpinned executable dependency loaded from a third-party package registry
Risk Level: Mediumbash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The skill instructs users to install
clawlink-pluginwithout specifying an immutable version, cryptographic digest, or signature-verification procedure. It then adds that plugin to the OpenClaw tool allowlist and restarts the gateway, causing the registry-selected package revision to become active.This creates a supply-chain trust dependency that cannot be fully assessed from the audited project because the plugin implementation is not included. A compromised registry, publisher account, package release, or distribution channel could replace the expected dependency with attacker-controlled code after this skill has been reviewed.
The risk is amplified by the plugin's intended role. The document states that ClawLink stores the user's OAuth token and injects it into proxied Google Calendar requests. The documented tool catalog includes access to calendar data and write operations such as creating or deleting events, changing access-control rules, and clearing calendars. The audit did not find evidence that the current plugin is malicious; the issue is the mutable, unverified installation mechanism.
Attack Path
- An attacker compromises the package publisher, registry, or another part of the plugin distribution chain.
- The attacker publishes a malicious release under the expected
clawlink-pluginpackage identity. - A user follows the skill instructions and installs the dependency without an immutable version or digest.
- OpenClaw resolves and installs the compromised release.
- The user adds the plugin to
tools.alsoAllow. - Restarting the gateway loads the attacker-controlled ...[truncated 909 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a reviewed, immutable version rather than installing the registry's current release.
- Verify the package with a cryptographic digest or trusted publisher signature before installation.
- Publish the expected version, digest, signing identity, source repository, and reproducible-build information in the skill documentation.
- Require explicit user approval before installing the plugin, modifying the tool allowlist, and restarting the gateway.
- Run the plugin with the least possible privileges, including narrowly scoped OAuth permissions and restricted filesystem, process, network, and secret access.
- Separate read-only calendar functionality from write and access-control functionality where supported.
- Retain the documented preview and confirmation requirements for all calendar writes, while enforcing them outside the potentially compromised plugin wherever possible.
- Audit plugin updates before deployment and prevent unattended upgrades to unreviewed releases.
- Provide revocation and incident-response instructions covering plugin removal, OAuth-token revocation, calendar permission review, and gateway restart.
