T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Handles Trello OAuth Credentials and API Requests
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12, 33, 47–49, and 71–77
Vulnerability Type: Third-party supply-chain and credential-proxy trust risk
Risk Level: MediumComplete Code Snippet
markdown This skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=trello-projects) for hosted connection flows and credentials so you do not need to configure Trello API access yourself.text │ │ 5. Proxy Requests │bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartmarkdown **No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Trello API request on the user's behalf. ### Getting Connected 1. Install the ClawLink plugin (see Install above). 2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet. 3. Open https://claw-link.dev/dashboard?add=trello and connect Trello. 4. Call `clawlink_list_integrations` to verify the connection is active.Technical Analysis
The skill directs users to install and explicitly allowlist an external plugin, restart the OpenClaw gateway, and authorize a hosted third-party service to store a Trello OAuth token and proxy API requests. The referenced plugin implementation is not present in the audited project, so its behavior cannot be independently verified from the available artifact.
The installation command does not pin an immutable plugin version, digest, or publisher signature. Consequently, the component installed in the future could differ from the component originally reviewed. The document describes the plugin as verified, but the audited instructions do not enforce integrity or provenance verification before installation.
Because the plugin is allowlisted as an Agent tool and the hosted service handles OAuth credentials, compromise of e ...[truncated 1753 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an immutable, reviewed version rather than installing an unqualified package reference.
- Require cryptographic verification through a trusted publisher signature and a documented package digest.
- Publish or link to the exact source revision corresponding to the installed artifact so the plugin can be independently audited.
- Display the requested Trello OAuth scopes before authorization and request only the minimum scopes needed for the selected operation.
- Document token storage, encryption, retention, rotation, revocation, incident-response, and tenant-isolation controls.
- Require explicit informed user consent before plugin installation, tool allowlisting, and OAuth authorization.
- Scope plugin access to the relevant skill or session instead of globally enabling it wherever platform controls permit.
- Provide clear instructions for uninstalling the plugin, removing it from
tools.alsoAllow, disconnecting Trello, and revoking the OAuth token. - Consider supporting a direct, locally configured Trello integration for users who do not want credentials or requests handled by an intermediary service.
- Re-audit the external plugin and hosted integration separately because their implementations are outside the supplied project.
