Back to skill

Security audit

Kleinanzeigen helper

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Kleinanzeigen listing helper with confirmation and scoping safeguards, though users should verify the external KleinClaw plugin before enabling it.

Install only if you trust the KleinClaw plugin source and are comfortable giving it control over configured listing workspaces and live Kleinanzeigen listing actions. Keep `adRoots` narrow, do not share credentials or config files in chat, and review the exact listing scope before confirming any mutating action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/install.md:3
Finding

Unpinned Third-Party Plugin Installation and Activation

Content
View full analysis

Vulnerability Details

File Location: references/install.md, lines 3–8 and 16–21
Vulnerability Type: Unpinned executable third-party dependency
Risk Level: Medium

Complete Code Snippet

markdown
- Install [KleinClaw](https://clawhub.ai/plugins/kleinclaw), then enable it:

  ```bash
  openclaw plugins install clawhub:kleinclaw
  openclaw plugins enable kleinclaw
  openclaw gateway restart
  • The plugin bundles the miniclaw runtime and this helper skill, so no separate executable path is required. The standalone kleinanzeigen-helper skill from ilyaZar/kleinanzeigen-helper is optional guidance only; the callable tools still come from the KleinClaw plugin.
text

### Technical Analysis

The installation procedure retrieves `clawhub:kleinclaw` without specifying an immutable version, release digest, checksum, or required signature. It then enables the installed plugin and restarts the gateway, causing its code to be loaded.

The documentation states that the plugin bundles the executable `miniclaw` runtime. That runtime is not included in this project, so its implementation and the exact artifact users will receive cannot be verified by auditing this repository alone. Because the package reference is mutable, the effective executable content may differ between installation times even when these reviewed instructions remain unchanged.

This is an insecure dependency and supply-chain boundary rather than evidence that the current KleinClaw package is malicious.

### Attack Path

1. An attacker compromises the package registry entry, publisher account, release pipeline, or another distribution component associated with `clawhub:kleinclaw`.
2. The attacker publishes a modified package under the same unversioned identifier.
3. A user follows the documented `openclaw plugins install clawhub:kleinclaw` command.
4. The package m
...[truncated 864 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin KleinClaw to a reviewed, immutable version and, where supported, a cryptographic artifact digest.
  2. Publish the expected checksum and provide a documented verification command before plugin enablement.
  3. Require package-signature verification and document the expected publisher identity or signing key.
  4. Link the pinned release to auditable source code and reproducible build information for the bundled miniclaw runtime.
  5. Separate installation from enablement so users can inspect the resolved package metadata, requested permissions, and integrity results before loading it.
  6. Apply least privilege to the OpenClaw/plugin process, narrowly scope adRoots, and restrict filesystem and browser-profile access to only what is required.
  7. Document a controlled upgrade process that reviews release notes, source changes, signatures, and hashes before changing the pinned version.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/non-negotiables.md (reported line 9)May include surrounding context.

md
- Do not ask for, read, print, summarize, store, inspect, or infer Kleinanzeigen
  usernames, passwords, SMS or 2FA codes, cookies, browser profiles, session
  data, or credential-bearing config files.
- Do not ask the user to paste `config.yaml`, browser settings, cookies, logs,
  or credential-like snippets.
- Keep `adRoots` narrow. Do not broaden `adRoots` or change `approvalMode` for
  convenience.

Static analysis

No suspicious patterns detected.