Back to skill

Security audit

KlickAnalytics CLI

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent KlickAnalytics CLI guide, but it asks users to install mutable external code and persist an API key in shell startup files without adequate safety guidance.

Install only if you trust KlickAnalytics and are comfortable running its external Python package. Prefer a dedicated virtual environment, pin a reviewed package version where possible, and avoid storing the API key directly in shell startup files on shared, synced, backed-up, or source-controlled machines; use a secret manager or tightly scoped environment injection instead.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:57
Finding

Unpinned Third-Party CLI Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 57–59
Vulnerability Type: Unpinned external package installation
Risk Level: Medium

bash
# 1. Install
pip install klickanalytics-cli

Technical Analysis

The Skill directs users to install klickanalytics-cli from the package index without specifying an exact version, validating a cryptographic hash, or providing a lock file. Consequently, the installed code can differ from the version that existed when the Skill was audited.

Python package installation may execute package-controlled build or installation logic. The installed ka executable also runs with the privileges and environment of the invoking user. Because the dependency implementation is not included in this project, its installation behavior and runtime handling of KLICKANALYTICS_CLI_API_KEY cannot be verified through this audit.

No evidence establishes that the current package is malicious. The vulnerability is the unaudited and mutable software supply-chain boundary created by installing an unpinned external package.

Attack Path

  1. An attacker compromises the package publisher account, package distribution channel, or a future release of klickanalytics-cli.
  2. The attacker publishes a release containing malicious installation or runtime behavior.
  3. A user follows the documented pip install klickanalytics-cli instruction.
  4. Pip resolves and installs the attacker-controlled release because no exact version or hash is enforced.
  5. Malicious code executes during installation or when the user invokes ka.
  6. The code operates with the installing or invoking user's privileges and may access that process's files, network connectivity, and environment variables.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user who installs or runs the package. The accessible scope may include user-owned files, network resources available to that account, and enviro ...[truncated 289 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an exact, reviewed version, for example:
    bash
    python -m pip install klickanalytics-cli==<reviewed-version>
    
  2. Publish an official requirements file containing trusted hashes and install it with:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Document the package's official source repository and release provenance so users can verify that the package-index artifact corresponds to reviewed source.
  4. Recommend installation in a dedicated virtual environment or similarly isolated runtime rather than the user's global Python environment.
  5. Review each dependency update before changing the pinned version, including package metadata, transitive dependencies, installation hooks, and runtime handling of credentials.
  6. Use a minimally privileged service account for scheduled or agent workflows and expose the API key only to the process that requires it.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation guidance is overly broad, instructing use whenever a user asks about the CLI, available commands, integrations, automation workflows, OpenClaw, or global asset coverage. This can cause the skill to be invoked in adjacent financial or agent-integration contexts where it may steer the conversation toward a vendor-specific tool unexpectedly, increasing prompt-scope hijacking risk and inappropriate tool promotion.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
98% confidence
Finding

Directing users to add the API key to ~/.bashrc or ~/.zshrc creates session-persistent secret storage in plaintext. Persistent shell configuration is a common source of credential leakage through filesystem access, backups, terminal support snapshots, or accidental publication, so this is a real secret-handling weakness.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
# 1. Install
pip install klickanalytics-cli

# 2. Set API key — add to ~/.bashrc or ~/.zshrc for persistence
export KLICKANALYTICS_CLI_API_KEY=your_api_key_here

# 3. Verify

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The setup instructions tell users to place an API key in shell startup files for persistence without warning that these files may be widely readable, synced, backed up, or exposed through logs and support bundles. Encouraging long-lived credential storage without safer alternatives increases the chance of accidental disclosure and credential reuse compromise.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.