Back to skill

Security audit

Clovercli

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Clover CLI guide, but it asks users to install changing third-party code and persist sensitive Clover credentials in a shell profile.

Review this skill carefully before installing. Use a pinned and verified CLI release where possible, avoid storing Clover access tokens in ~/.bashrc, prefer a credential manager or per-command environment variable, use least-privilege and revocable Clover tokens, and remove real client identifiers from shared documentation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:9
Finding

Unpinned Third-Party Package and Repository Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:17
Finding

Persistent Plaintext Storage of Clover Access Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:151
Finding

Embedded Merchant Identifier and Personal Relationship Information

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The setup instructions tell users to place a long-lived access token in ~/.bashrc, which causes the credential to persist across sessions in a plaintext shell startup file. This increases exposure to local compromise, accidental disclosure through backups/dotfile syncing, or leakage during troubleshooting and screen sharing; in this skill context the token grants access to Clover merchant data, making persistence more sensitive.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
git clone https://github.com/Versatly/clovercli.git
cd clovercli && npm install && npm run build

# Set credentials (add to ~/.bashrc)
export CLOVER_ACCESS_TOKEN="your-token"
export CLOVER_MERCHANT_ID="your-merchant-id"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation includes a specific merchant ID tied to a named client and business description, which exposes customer-identifying operational information without any minimization or privacy guidance. Even if the merchant ID is not a secret credential by itself, publishing real client identifiers and contextual business details can enable profiling, targeted phishing, social engineering, or correlation with other leaked data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.