Back to skill

Security audit

Supalytics - Web Analytics

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a normal analytics CLI helper, but its install and troubleshooting instructions ask for risky system-level and unverified code execution steps.

Review the install path before using this skill. Prefer a pinned, verified Bun and Supalytics CLI installation, avoid piping remote scripts into a shell, and do not create sudo symlinks in /usr/local/bin unless you understand the system-wide impact. Treat site add/update/remove commands as administrative actions that should require explicit user approval.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:17
Finding

Remote Bun Installer Is Downloaded and Executed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 17
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Complete Code Snippet:

bash
# Install Bun first
curl -fsSL https://bun.sh/install | bash
export PATH="$HOME/.bun/bin:$PATH"

Technical Analysis

The installation instructions pipe a remotely retrieved script directly into bash. Although bun.sh is the official Bun domain and HTTPS provides transport protection, the downloaded script is mutable and is neither pinned to a specific release nor checked against a cryptographic digest or signature.

Consequently, the code actually executed can differ from the content reviewed in this Skill. The shell receives the current response from the remote endpoint with the permissions of the user following the instructions. The -f, -s, -S, and -L options affect HTTP behavior but do not authenticate the contents of the script beyond ordinary TLS validation.

This exceeds the minimum privilege needed to document or invoke the Supalytics CLI. Installing a runtime may be necessary when Bun is absent, but immediate execution of an unverified, mutable response is not necessary.

Attack Path

  1. A user or agent follows the installation instructions.
  2. curl requests the current installer from https://bun.sh/install.
  3. If the hosting account, CDN, DNS/TLS trust chain, or upstream installer is compromised, the response can contain attacker-controlled shell commands.
  4. The response is passed directly to bash without review or integrity validation.
  5. The payload executes with the invoking user's permissions and can modify files, credentials, shell configuration, or installed tools available to that account.

Impact Assessment

Successful exploitation provides arbitrary command execution as the user running the installation command. This can expose that user's analytics credentials, OAuth tokens, source code, ...[truncated 251 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pipe a network response directly into a shell.
  • Prefer an operating-system package manager or a documented, version-pinned Bun release.
  • Download the installer or release artifact to a local file, verify a publisher-provided cryptographic signature or SHA-256 digest, inspect it, and only then execute it.
  • Pin the expected Bun version rather than relying on the latest mutable installer.
  • Run installation as an unprivileged user and clearly warn users not to invoke the installer with sudo.
  • Treat runtime installation as a user-confirmed prerequisite rather than automatically executing it in an agent context.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:21
Finding

Supalytics CLI Is Installed Globally Without a Pinned Version or Integrity Constraint

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 21
Vulnerability Type: Insecure dependency installation
Risk Level: Medium

Complete Code Snippet:

bash
# Install Supalytics CLI
bun add -g @supalytics/cli

Technical Analysis

The command globally installs the current registry-selected version of @supalytics/cli. No exact version, lockfile, package digest, provenance requirement, or signature verification is specified. The effective code can therefore change over time without any corresponding change to this Skill.

Package installation can execute package lifecycle logic and places executable code in a globally used Bun location. A compromised publisher account, malicious newly published release, registry compromise, or compromised transitive dependency could introduce arbitrary code during installation or later CLI execution.

A global installation also increases exposure compared with a project-local, version-locked dependency because the resulting command is made broadly available to the user.

Attack Path

  1. An attacker compromises the package publisher, a dependency publisher, or the package distribution channel.
  2. A malicious release becomes the version selected by the unpinned package specification.
  3. A user or agent runs bun add -g @supalytics/cli.
  4. Attacker-controlled package or lifecycle code executes with the installing user's permissions.
  5. The installed CLI can subsequently access authentication state and analytics data whenever it is invoked.

Impact Assessment

Exploitation can result in arbitrary code execution as the installing user and compromise Supalytics OAuth credentials or tokens accessible to the CLI. It may also expose analytics, revenue, conversion, and site-management data, along with unrelated files and credentials available to the account. The global scope makes the compromised executable available beyond a single isolated project.

Remediation
View remediation

Remediation Suggestions

  • Pin @supalytics/cli to an exact, reviewed version.
  • Publish and verify package checksums, signatures, or registry provenance where supported.
  • Use a lockfile and review the complete transitive dependency graph before deployment.
  • Prefer a project-local or isolated installation over a global installation where operationally possible.
  • Disable or restrict dependency lifecycle scripts when the package manager and package permit it.
  • Document a controlled update process that reviews new releases before changing the pinned version.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:239
Finding

Root-Owned System Command Links Target User-Writable Executables

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 239-240
Vulnerability Type: Privileged system-path modification and tool hijacking
Risk Level: High

Complete Code Snippet:

bash
sudo ln -sf ~/.bun/bin/bun /usr/local/bin/bun
sudo ln -sf ~/.bun/bin/supalytics /usr/local/bin/supalytics

Technical Analysis

These commands use sudo and the force option to create or replace entries in /usr/local/bin. They therefore modify a system-wide executable search path with root privileges. The links point into the invoking user's home directory, where the target files ordinarily remain writable by that user and can also be replaced by future global package installations.

This creates a trust-boundary mismatch: root creates trusted-looking system commands whose effective contents are controlled by an unprivileged account. The -f option can also overwrite existing links or path entries without requiring the user to review what is being replaced.

System-wide links are not required merely to query analytics. A daemon-specific absolute executable path, a controlled service environment, or a root-managed installation would satisfy the stated PATH requirement with less privilege.

Attack Path

  1. The user follows the troubleshooting instructions and authorizes both sudo ln -sf commands.
  2. /usr/local/bin/bun and /usr/local/bin/supalytics resolve to files under that user's home directory.
  3. The user account, a compromised package update, or another process with write access to the home-directory targets replaces either executable.
  4. Another user, daemon, administrator, or privileged automation resolves the command through /usr/local/bin.
  5. The replacement code executes with the privileges and data access of that invoking process.

Impact Assessment

The immediate commands require explicit sudo authorization and do not independently grant the target programs root privileges. However, ...[truncated 374 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the sudo ln -sf recommendation.
  • Configure the OpenClaw daemon with an explicit, narrowly scoped PATH or an absolute path to the executable.
  • If a system-wide installation is necessary, copy a pinned and verified executable into a root-owned directory rather than linking to a user-writable location.
  • Ensure both the system-path entry and its executable target are owned by root and are not writable by unprivileged users.
  • Avoid force-overwriting existing path entries; first inspect the destination and fail safely if it already exists.
  • Run the analytics CLI under a dedicated unprivileged service account with access only to the required credentials and resources.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

Piping a remote script directly from curl into bash executes code fetched over the network without review, pinning, or integrity verification. In an agent or automated environment, this is especially dangerous because it enables supply-chain compromise or remote code execution if the source, transport, or install script is tampered with.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

bash
# Install Bun first
curl -fsSL https://bun.sh/install | bash
export PATH="$HOME/.bun/bin:$PATH"

# Install Supalytics CLI

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The shell pipeline | bash turns downloaded content directly into executed commands, removing any opportunity for inspection and amplifying the risk of command chaining abuse. In a skill document that may guide an autonomous or semi-autonomous agent, this pattern materially raises the chance of unintended arbitrary code execution.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

bash
# Install Bun first
curl -fsSL https://bun.sh/install | bash
export PATH="$HOME/.bun/bin:$PATH"

# Install Supalytics CLI

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is described as query-only analytics tooling, but the documentation also includes site-management actions such as creating, updating, setting defaults, and removing sites. In an agent setting, this scope expansion increases the chance the agent performs state-changing or destructive actions the user did not intend, especially the removal command.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation instructs users or agents to create system-wide symlinks in /usr/local/bin using sudo, which modifies trusted executable resolution outside the analytics-query task. In an agent context, privileged filesystem changes can be abused to alter command execution paths, persist tooling, or replace binaries with malicious ones.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The sudo ln -sf guidance requests elevated privileges without warning that it changes system binaries and affects all users/processes on the host. In agent environments, normalizing undocumented sudo usage can lead to unsafe escalation attempts and unintended modification of trusted paths.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
96% confidence
Finding

This line invokes sudo to place the bun executable into /usr/local/bin, requiring root privileges and modifying a trusted command location. If executed by an agent or copied blindly by a user, it creates unnecessary privilege exposure and could be substituted with a malicious binary or abused for persistence.

Content

Scanner excerpt · SKILL.md (reported line 239)May include surrounding context.

Bun installs to ~/.bun/bin which isn't in PATH for daemon processes like OpenClaw. After installation, symlink to system path:

bash
sudo ln -sf ~/.bun/bin/bun /usr/local/bin/bun
sudo ln -sf ~/.bun/bin/supalytics /usr/local/bin/supalytics

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
96% confidence
Finding

This line uses sudo to symlink supalytics into /usr/local/bin, again performing a privileged system-wide executable change. In the context of an AI agent skill, embedding root-required commands materially increases risk because the action is unrelated to the core read-only analytics function and can persist beyond the session.

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

bash
sudo ln -sf ~/.bun/bin/bun /usr/local/bin/bun
sudo ln -sf ~/.bun/bin/supalytics /usr/local/bin/supalytics

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest presents the skill as a tool to query analytics data, but the file also instructs agents to run login and init flows that open browsers, create sites, and handle OAuth device authorization. While some authentication may be an implementation detail, site creation via init is broader than the declared query-focused scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.