T08 · Insecure Dependencies
- Location
SKILL.md:42- Finding
Unpinned Third-Party Plugin Is Granted Access to OAuth-Mediated Spreadsheet Operations
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 42–50 and 71–79
Vulnerability Type: Unpinned and unauditable third-party dependency
Risk Level: MediumVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartThe same file describes the plugin's authentication role:
text All Google Sheets tool calls are authenticated automatically by ClawLink using the user's connected Google account. No API key is required in chat. ClawLink stores the OAuth token securely and injects it into every Google Sheets API request on the user's behalf.Technical Analysis
The installation command identifies
clawlink-pluginonly by a mutable registry name. It does not pin an immutable version or cryptographic digest, verify a publisher signature, or provide locally auditable plugin source code. The instructions then add that plugin to the tool allowlist and restart the gateway so that it is loaded.This creates a supply-chain trust gap: the behavior installed at execution time can differ from the artifact reviewed in this audit. The dependency occupies a sensitive boundary because it supports a hosted OAuth flow and proxies operations against spreadsheets in the connected Google account.
The reviewed file explicitly discloses this architecture and requires user confirmation for write operations. There is no evidence that the current package steals credentials or intentionally misuses data. The risk arises from the inability to establish that the subsequently downloaded plugin is immutable and equivalent to a reviewed implementation.
Attack Path
- An attacker compromises the plugin publisher account, distribution registry, build pipeline, or an upstream component used by
clawlink-plugin. - The attacker publishes a modified artifact under the same unversioned plugin name.
- A user follows
SKILL.mdand runs `opencla ...[truncated 1265 chars]
- An attacker compromises the plugin publisher account, distribution registry, build pipeline, or an upstream component used by
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an immutable, reviewed version rather than installing it only by package name.
- Verify a cryptographic digest and publisher signature before installation.
- Publish the corresponding plugin source code and provide reproducible-build instructions so reviewers can verify that the distributed artifact matches the source.
- Maintain a signed software bill of materials and continuously scan the plugin and its transitive dependencies.
- Grant only the minimum Google OAuth scopes required for the requested spreadsheet operation.
- Document token storage, encryption, retention, access controls, revocation, and incident-response procedures.
- Isolate the plugin with restrictive filesystem, process, and outbound-network permissions.
- Preserve explicit user approval before installation, account pairing, and every write operation.
- Show the target spreadsheet, range, operation, and proposed values in a preview before requesting write approval.
- Provide a straightforward procedure to revoke the Google connection, remove the plugin allowlist entry, and uninstall the plugin.
