T08 · Insecure Dependencies
- Location
SKILL.md:45- Finding
Unpinned Privileged Third-Party Plugin Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 45-47; repeated configuration at lines 368-369
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code:
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The Skill directs the agent to install, explicitly allowlist, and activate the external
clawlink-plugin. The plugin's implementation is not included in the audited project, and the installation command does not pin an immutable version or verify a cryptographic checksum.Consequently, the code that ultimately processes credentials and performs Slack operations can differ from what was reviewed in this package. Restarting the gateway activates the unaudited dependency. Although the audit found no evidence that the referenced plugin is malicious, this design creates a supply-chain trust boundary that cannot be validated from the Skill itself.
Attack Path
- A user asks to enable the Slack Skill.
- The agent installs
clawhub:clawlink-pluginwithout an immutable version or integrity check. - The agent adds the plugin to
tools.alsoAllow. - The gateway is restarted, loading the externally supplied implementation.
- If the package source, publisher account, distribution infrastructure, or plugin release is compromised, attacker-controlled code runs with the plugin's granted tool access.
- The compromised plugin can intercept Slack requests, misuse connected credentials, or alter requested operations.
Impact Assessment
A compromised dependency could access data available through the connected Slack authorization, including messages, files, user information, and workspace metadata. Depending on granted OAuth scopes, it could also send or delete messages, modify channels, administer user groups, invite users, or access audit ...[truncated 172 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to a reviewed, immutable version rather than installing a mutable package reference.
- Verify the package using a cryptographic digest or signed provenance record before installation.
- Include the plugin source, permission manifest, and dependency lockfile in the review scope.
- Require explicit, informed user approval before installation, allowlisting, and gateway restart.
- Document the publisher-verification process and provide commands for disabling and uninstalling the plugin.
- Run the plugin in a sandbox with narrowly constrained network, filesystem, process, and tool permissions.
- Monitor installed plugin versions and alert users before upgrades change the reviewed implementation.
