Back to skill

Security audit

LobsterBio - Use

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Lobster AI bioinformatics guide, but it asks users to install mutable third-party code and persist provider credentials while sending work to external services.

Review before installing. Use an isolated environment, prefer a pinned Lobster version and only the domain extra you need, avoid global config unless necessary, and do not provide patient data, regulated identifiers, unpublished sensitive research details, or high-value API keys unless you are comfortable with the documented LLM provider and public database network access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:111
Finding

Unpinned Installation of Lobster AI with Broad Optional Dependencies

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/cli-reference.md:9
Finding

Unconstrained Dependency Installation and Upgrade Instructions

Content
View full analysis
Remediation
View remediation
`. 2. Publish a lockfile or fully hashed requirements file covering domain packages and all transitive dependencies. 3. Separate installation from initialization so users can inspect and verify the resolved dependency set before executing the CLI. 4. Pin packages supplied through `uv tool --with` as well as the primary package. 5. Prefer isolated environments and prohibit root or administrator installation unless explicitly necessary. 6. Replace generic upgrade instructions with a controlled update procedure that verifies signatures or hashes and reviews release changes. 7. Recommend targeted extras rather than `[full]` whenever the requested analysis does not require every optional component. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (18)

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Declaring writes to .lobster_workspace/.env means the skill is designed to materialize credentials inside the analysis workspace. That is dangerous because the workspace also contains session data and outputs and may be inspected, archived, shared, or processed by other agents or commands, creating a realistic path for secret exposure and downstream abuse of LLM provider accounts.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
only that provider's env var(s). Paired credentials (AWS, Azure) must both be set.
declared_writes:
  - .lobster_workspace/                        # Workspace data, session state, outputs
  - .lobster_workspace/.env                    # Provider credential (workspace-scoped, mode 0600)
  - .lobster_workspace/provider_config.json    # Provider selection config
  - ~/.config/lobster/credentials.env          # ONLY if --global flag is used (not default)
  - ~/.config/lobster/providers.json           # ONLY if --global flag is used (not default)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill explicitly documents writing provider credentials to persistent files such as workspace-scoped .env and optional global ~/.config/lobster/credentials.env. Persisting API keys in agent-accessible workspaces increases the risk of credential disclosure through later tool use, accidental inclusion in outputs, workspace exfiltration, or reuse by other processes, especially because this skill also performs networked operations.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
- .lobster_workspace/                        # Workspace data, session state, outputs
  - .lobster_workspace/.env                    # Provider credential (workspace-scoped, mode 0600)
  - .lobster_workspace/provider_config.json    # Provider selection config
  - ~/.config/lobster/credentials.env          # ONLY if --global flag is used (not default)
  - ~/.config/lobster/providers.json           # ONLY if --global flag is used (not default)
network_access:
  - docs.omics-os.com                          # On-demand documentation fetches

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cli-reference.md (reported line 30)May include surrounding context.

Non-interactive init (agents can run this):

Credential safety: Always pass API keys via environment variables, never as raw strings. Keys are written to workspace .env (mode 0600) or ~/.config/lobster/credentials.env.

bash
# Anthropic (most common)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cli-reference.md (reported line 87)May include surrounding context.

Non-interactive init (agents can run this):

Credential safety: Always pass API keys via environment variables, never as raw strings. Keys are written to workspace .env (mode 0600) or ~/.config/lobster/credentials.env.

bash
# Anthropic (most common)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cli-reference.md (reported line 89)May include surrounding context.

Non-interactive init (agents can run this):

Credential safety: Always pass API keys via environment variables, never as raw strings. Keys are written to workspace .env (mode 0600) or ~/.config/lobster/credentials.env.

bash
# Anthropic (most common)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/cli-reference.md (reported line 73)May include surrounding context.

md
| Flag | Purpose |
|------|---------|
| `--global` | Save to `~/.config/lobster/` instead of workspace — writes global config |
| `--force` | Overwrite existing config (creates timestamped backup first) |
| `--cloud-key <key>` | Omics-OS Cloud API key (premium tier) |

**Check if already configured**:

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/cli-reference.md (reported line 258)May include surrounding context.

md
| `/session` | Current session info (ID, messages, data) |
| `/save [--force]` | Save all modalities to workspace |
| `/export [--no-png]` | Export session data + plots to `exports/` |
| `/clear` | Clear conversation history |
| `/reset` | Reset conversation (retains loaded data) |
| `/status` | Subscription tier, packages, agents |
| `/tokens` | Token usage and costs |

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/cli-reference.md (reported line 259)May include surrounding context.

md
| `/save [--force]` | Save all modalities to workspace |
| `/export [--no-png]` | Export session data + plots to `exports/` |
| `/clear` | Clear conversation history |
| `/reset` | Reset conversation (retains loaded data) |
| `/status` | Subscription tier, packages, agents |
| `/tokens` | Token usage and costs |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cli-reference.md (reported line 286)May include surrounding context.

lobster config show-config # Full runtime config lobster config create-custom # Interactive custom config lobster config models # Per-agent model config lobster config generate-env # Generate .env template

text

## Session Management

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest declares many generic trigger phrases such as "cluster," "run QC," "feature selection," and especially "bioinformatics," without narrowing context or giving exclusion conditions. Because this is a markdown/manifest file and the trigger scope is very broad, the skill could be invoked unintentionally during normal scientific or data-analysis discussion.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L164 states that only the Research Agent has internet access, yet the same file documents network-dependent behavior elsewhere, including on-demand docs fetches from docs.omics-os.com and provider API access for the platform. It also describes a Data Expert that performs dataset downloads and a Protein Structure Viz agent that fetches PDB data, which contradicts the absolute claim in the hard rule.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explicitly instructs agents to perform internet-backed literature and dataset searches, but it does not warn that prompts, search terms, and possibly dataset identifiers may be transmitted to external services. In a bioinformatics context, users may include unpublished study topics, patient-associated metadata, or sensitive research intent in queries, creating a real privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents lobster purge as removing Lobster files, but it does not include a clear user warning about the scope and impact of deleting local files. For markdown files, safety-relevant behaviors that may affect user data or system state should be accompanied by an explicit warning, especially when the command is destructive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The /queue clear [type] command removes queue entries, which is a potentially destructive action affecting user workflow state. The markdown reference presents the command without any cautionary note about permanence or recoverability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

/metadata clear appears to remove metadata entries, which can alter or erase stored workspace/session state. The description does not include a caution about data loss or whether the action can be undone.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The document tells users to initialize the tool non-interactively using ANTHROPIC_API_KEY from the environment, but it does not include a warning that the skill accesses sensitive credentials during setup. Markdown guidance should disclose credential-sensitive behavior when it may affect user privacy or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The /open <file> command launches the selected file in the system default app, which affects the local system and may invoke external applications. The reference lists the behavior but does not warn users that this will open software outside the CLI context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

/clear and /reset alter conversational state, and /clear in particular may remove context that users expect to retain. The reference describes the commands tersely without warning that session history or context may be lost.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.