Back to skill

Security audit

wolt-cli

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Wolt CLI helper, but it deserves review because it asks users to handle live Wolt credentials in command-line commands and stores refreshed credentials locally without enough safety detail.

Review this before installing if you will use a real Wolt account. Prefer a pinned, verified version of the CLI; avoid pasting tokens or cookies into shared terminals, logs, screenshots, or shell-history-recorded commands; confirm where the CLI stores credentials and restrict file permissions; rotate or revoke credentials after testing; and double-check any cart, favorite, or address mutation before confirming it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned Third-Party Repository Used for Setup and Build Instructions

Content
View full analysis
[flags] ``` ``` `references/command-reference.md:5-11`: ```markdown Tool repository: https://github.com/mekedron/wolt-cli Open the repository for setup/build details, then use the local binary: ```bash wolt [flags] ``` ``` ### Technical Analysis The Skill delegates setup and build instructions to the current contents of a mutable third-party GitHub repository. It does not pin a reviewed release, tag, or commit and provides no checksum or signature verification procedure. Consequently, the software and installation instructions used at execution time may differ from those that existed when the Skill was reviewed. Compromise of the repository, its maintainer account, its release process, or one of its transitive dependencies could introduce attacker-controlled build or installation behavior. The reviewed package does not itself download or execute remote code, so this is classified as an insecure dependency and supply-chain weakness rather than confirmed remote payload execution. ### Attack Path 1. An attacker compromises the linked repository, its maintainer account, release artifacts, or dependency chain. 2. The attacker changes the setup instructions or source code to include malicious commands. 3. A user or Agent follows the Skill's direction to open the repository and use its current setup or build instructions. 4. The altered component is built or installed locally. 5. Malicious code executes with the privileges of the user performing the installation or running the CLI. ### Impact Assessment Success ...[truncated 434 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:39
Finding

Authentication Credentials Exposed Through Command-Line Arguments

Content
View full analysis
" --wrtoken "" --overwrite wolt profile status --profile default --format json --verbose ``` ``` `references/command-reference.md:13-19`: ```markdown - `--format table|json|yaml` - `--profile ` - `--address ""` - `--locale ` - `--no-color` - `--wtoken ` - `--wrtoken ` - `--cookie ` (repeatable) ``` `references/command-reference.md:29`: ```markdown - `wolt configure --profile-name [--wtoken ...] [--wrtoken ...] [--cookie ...] [--overwrite]` ``` `references/workflows.md:4-8`: ```bash ## 1) Authenticate and Validate Session ```bash wolt configure --profile-name default --wtoken "" --wrtoken "" --overwrite wolt profile status --profile default --format json --verbose wolt profile show --profile default --format json ``` ``` ### Technical Analysis The documented authentication workflow instructs users to place access tokens and refresh tokens directly in command-line arguments. The command reference also permits session cookies to be supplied in the same manner. Command-line secrets may be recorded in interactive shell history, terminal transcripts, automation logs, debugging output, or process-monitoring systems. On operating systems where process arguments are visible to other local users or monitoring agents, credentials may also be exposed while the command is running. Refresh tokens and session cookies are particularly sensitive because they may provide persistent or renewable authenticated access. Although the documentation states t ...[truncated 1386 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The skill explicitly describes handling access tokens, refresh tokens, cookies, and automatic token refresh with persistence back to local config. In an agent context, this increases the chance that highly sensitive credentials are exposed to the model, passed on the command line, stored insecurely, surfaced in logs, or reused beyond the user's intended scope.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
2. Selected profile auth fields
3. Default profile auth fields

When refresh credentials are available, expired/401 access tokens are refreshed automatically and persisted back to local config.

## Location Rules

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description says to trigger when asked to 'find food on Wolt' and to 'debug Wolt auth/location/output behavior,' but it does not provide a bounded list of trigger phrases or exclusion cases. While Wolt is domain-specific, the activation guidance is still broad enough that many general food-search or troubleshooting requests could cause unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The command reference explicitly documents passing authentication tokens, refresh tokens, and cookies on the command line but does not warn that these secrets may be exposed through shell history, process listings, terminal logs, or transcripts. In a skill meant for agent-assisted terminal use, this increases the chance that long-lived session material is mishandled or leaked during normal usage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The configure command is described as writing local profile auth config, but the documentation gives no indication where credentials are stored, whether they are encrypted, or what filesystem permissions are expected. That omission can lead users or agent workflows to persist live authentication material insecurely on disk without understanding the exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill description lists address modification commands, including add, update, remove, and use, which can change persistent account state and potentially affect deliveries. The markdown does not provide any warning that these operations alter saved user data or may change the default/active address context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow embeds credential-bearing commands using access and refresh tokens directly on the command line without any warning about secret handling. Command-line secrets can be exposed through shell history, process listings, terminal logs, screenshots, or agent transcripts, which is especially risky here because the skill is specifically designed to operate on a user's Wolt account.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The example response hard-codes "locale": "en-FI", which can imply a fixed language/locale expectation. Under the policy rule, forcing a specific locale without user opt-in can be a natural-language policy concern unless the constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.