T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Unpinned Third-Party Package and Repository Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Clover CLI guide, but it asks users to install changing third-party code and persist sensitive Clover credentials in a shell profile.
Review this skill carefully before installing. Use a pinned and verified CLI release where possible, avoid storing Clover access tokens in ~/.bashrc, prefer a credential manager or per-command environment variable, use least-privilege and revocable Clover tokens, and remove real client identifiers from shared documentation.
SKILL.md:9Unpinned Third-Party Package and Repository Installation
SKILL.md:17Persistent Plaintext Storage of Clover Access Credentials
SKILL.md:151Embedded Merchant Identifier and Personal Relationship Information
The setup instructions tell users to place a long-lived access token in ~/.bashrc, which causes the credential to persist across sessions in a plaintext shell startup file. This increases exposure to local compromise, accidental disclosure through backups/dotfile syncing, or leakage during troubleshooting and screen sharing; in this skill context the token grants access to Clover merchant data, making persistence more sensitive.
git clone https://github.com/Versatly/clovercli.git
cd clovercli && npm install && npm run build
# Set credentials (add to ~/.bashrc)
export CLOVER_ACCESS_TOKEN="your-token"
export CLOVER_MERCHANT_ID="your-merchant-id"
The documentation includes a specific merchant ID tied to a named client and business description, which exposes customer-identifying operational information without any minimization or privacy guidance. Even if the merchant ID is not a secret credential by itself, publishing real client identifiers and contextual business details can enable profiling, targeted phishing, social engineering, or correlation with other leaked data.
No suspicious patterns detected.