Back to skill

Security audit

Vinted

Security checks for vulnerabilities and agentic risk

Overview

This Vinted helper is a coherent marketplace workflow skill that stores optional local notes and uses Vinted only with user approval.

Install only if you are comfortable with a local ~/vinted/ note folder. Keep persistence off unless useful, avoid saving personal buyer details or sensitive shipping proof, and review any suggested related skill install or sync before approving it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:155
Finding

Unpinned Third-Party Skill Installation and Synchronization

Content
View full analysis
` if user confirms: - `ecommerce` - Build full-funnel commerce systems beyond one marketplace. - `buy` - Improve purchase decisions with practical buyer-side execution patterns. - `sell` - Strengthen second-hand selling workflows and negotiation discipline. - `pricing` - Run margin-safe pricing, discount, and offer frameworks. - `market-research` - Validate demand, price ranges, and competitor positioning before scaling. ## Feedback - If useful: `clawhub star vinted` - Stay updated: `clawhub sync` ``` ### Technical Analysis The Skill recommends installing third-party components by mutable slug and synchronizing installed Skills without specifying: - Exact versions - Trusted publisher identities - Cryptographic signatures - Package checksums - Immutable source references - Permission review requirements - Security review requirements before activation User confirmation prevents completely silent installation, but confirmation alone does not verify the integrity or behavior of the resolved package. A package associated with one of these slugs could be replaced, compromised, transferred to another publisher, or changed after this project was audited. The unrestricted `clawhub sync` recommendation creates a similar risk because a previously reviewed dependency may receive materially different instructions or executable content during a later synchronization. ### Attack Path 1. An attacker compromises a publisher account, registry entry, or distribution channel associated with a recommended Skill slug. 2. The attacker publishes a malicious package or update under that trusted-looking slug. 3. The Vinted Skill recommends that the user run `clawhub install ` or `clawhub sync`. ...[truncated 1252 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
memory-template.md:75
Finding

Plaintext Persistence of Marketplace and Buyer-Related Records

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · memory-template.md (reported line 15)May include surrounding context.

md
integration: pending | done | declined

## Profile
<!-- Buyer, casual seller, or pro reseller -->
<!-- Categories, brands, sizing rules, and operating style -->

## Current Priorities

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs creation of persistent files under ~/vinted that store profile details, pricing rules, risk notes, buyer information, and shipping/dispute data, but provides no warning, minimization guidance, or consent boundary for local retention. Even if this is not overtly malicious, it creates unnecessary privacy and security risk by encouraging durable storage of potentially sensitive marketplace and customer information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup instructions define activation boundaries broadly enough that the skill could trigger on loosely related topics like resale, closet cleanup, or second-hand fashion selling, rather than only explicit Vinted tasks. In an agent system, this can cause inappropriate routing, unexpected intervention, and collection or use of marketplace-related context when the user did not clearly request this skill, increasing the risk of overreach and privacy or workflow errors.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.