Skip to content

fix: harden OpenClaw plugin installation and security disclosure - #33

Open
TristanIsK wants to merge 3 commits into
lexmount:mainfrom
TristanIsK:codex/openclaw-security-review
Open

TristanIsK wants to merge 3 commits into
lexmount:mainfrom
TristanIsK:codex/openclaw-security-review

Conversation

@TristanIsK

@TristanIsK TristanIsK commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Problem and change

ClawHub's review of the OpenClaw 1.2.0 plugin flagged a download-and-execute trust boundary, overridable download sources, incomplete artifact provenance and unclear permissions. This adds the existing OpenClaw wrapper to current main as plugin 1.2.1 and hardens the shared installer without changing CLI runtime code.

  • Pin official CLI 1.2.3 SHA-256 digests for macOS arm64, Linux x86_64 and Windows x64 in the shipped scripts; reject source/version/install-path environment overrides before network access. Invalid downloads cannot replace or execute the installed binary.
  • Explain native installation, credential scope, host permission limits and approval requirements beside destructive commands; include exact release/source links for review.
  • Package only the wrapper, Skill, references/scripts, README and license. No binaries, credentials, install hooks or extra tools.

Validation

  • Four offline bootstrap security tests pass locally, covering overrides, tampering, symlinks and successful macOS/Linux script paths.
  • Actual macOS COS installation verifies the pinned digest and runs CLI 1.2.3 successfully.
  • All four CI jobs pass at 6650e9cf29ab5f18d5e74b90e6e5d4cea62cc8cd: test (including pinned Linux bootstrap), windows-bootstrap, linux-release and windows-release. Windows installation CI is not full Windows client acceptance.
  • Official package validation and source-bound publishing preflight pass. All 15 archive files match the final source commit byte-for-byte.
  • Fresh OpenClaw 2026.7.1 conversations verify the initial installation-consent prompt and, after installation authorization, CLI 1.2.3 installation, LexMount cloud session creation, reading Example Domain and closing the session. Marketplace review remains separate.

No automated merge. This is a new branch based on current main; previously published standalone Skill packages are unchanged.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant