T08 · Insecure Dependencies
- Location
SKILL.md:49- Finding
Unpinned Third-Party Plugin Is Installed and Persistently Allowlisted
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:49-53
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restartTechnical Analysis
The installation command identifies the ClawLink plugin only by its mutable registry name. It does not pin an exact version, content digest, verified signature, or immutable source revision. The subsequent command permanently adds the plugin to the allowed tool configuration, and the gateway restart loads it into the OpenClaw environment.
As a result, the code reviewed during this audit may differ from the code installed later. A compromised registry account, malicious package update, or supply-chain compromise could cause users to install altered plugin code without any corresponding change to this Skill file.
This is especially sensitive because the plugin mediates OAuth-authenticated Google Calendar operations, including reading event information and performing calendar write operations.
Attack Path
- An attacker compromises the plugin publisher, distribution registry, or release process.
- The attacker publishes a malicious release under the existing
clawlink-pluginpackage name. - A user follows the Skill instructions and runs the unversioned installation command.
- The mutable package reference resolves to the malicious release.
- The plugin is added to
tools.alsoAllow, and the gateway restart loads it. - The malicious plugin executes within its granted tool context and may intercept calendar data, OAuth-mediated requests, or calendar operations.
Impact Assessment
Exploitation could grant attacker-controlled plugin code access to the privileges available to the installed integration. Depending on the OAuth scopes and plugin runtime permis ...[truncated 575 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the plugin to an exact, reviewed version.
- Verify the package using a cryptographic digest or trusted publisher signature before installation.
- Publish a reproducible source repository and associate each release with a source commit.
- Document the plugin's complete runtime permissions and requested Google OAuth scopes.
- Apply least privilege by requesting only the calendar scopes required for the selected operations.
- Avoid persistent global allowlisting when a session-scoped or narrowly scoped authorization mechanism is available.
- Require explicit administrator approval before installation or upgrade.
- Establish a controlled update process that reviews permission and behavior changes before deploying new releases.
