T08 · Insecure Dependencies
- Location
SKILL.md:111- Finding
Unpinned Installation of Lobster AI with Broad Optional Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Lobster AI bioinformatics guide, but it asks users to install mutable third-party code and persist provider credentials while sending work to external services.
Review before installing. Use an isolated environment, prefer a pinned Lobster version and only the domain extra you need, avoid global config unless necessary, and do not provide patient data, regulated identifiers, unpublished sensitive research details, or high-value API keys unless you are comfortable with the documented LLM provider and public database network access.
SKILL.md:111Unpinned Installation of Lobster AI with Broad Optional Dependencies
references/cli-reference.md:9Unconstrained Dependency Installation and Upgrade Instructions
Declaring writes to .lobster_workspace/.env means the skill is designed to materialize credentials inside the analysis workspace. That is dangerous because the workspace also contains session data and outputs and may be inspected, archived, shared, or processed by other agents or commands, creating a realistic path for secret exposure and downstream abuse of LLM provider accounts.
only that provider's env var(s). Paired credentials (AWS, Azure) must both be set.
declared_writes:
- .lobster_workspace/ # Workspace data, session state, outputs
- .lobster_workspace/.env # Provider credential (workspace-scoped, mode 0600)
- .lobster_workspace/provider_config.json # Provider selection config
- ~/.config/lobster/credentials.env # ONLY if --global flag is used (not default)
- ~/.config/lobster/providers.json # ONLY if --global flag is used (not default)
The skill explicitly documents writing provider credentials to persistent files such as workspace-scoped .env and optional global ~/.config/lobster/credentials.env. Persisting API keys in agent-accessible workspaces increases the risk of credential disclosure through later tool use, accidental inclusion in outputs, workspace exfiltration, or reuse by other processes, especially because this skill also performs networked operations.
- .lobster_workspace/ # Workspace data, session state, outputs
- .lobster_workspace/.env # Provider credential (workspace-scoped, mode 0600)
- .lobster_workspace/provider_config.json # Provider selection config
- ~/.config/lobster/credentials.env # ONLY if --global flag is used (not default)
- ~/.config/lobster/providers.json # ONLY if --global flag is used (not default)
network_access:
- docs.omics-os.com # On-demand documentation fetches
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Non-interactive init (agents can run this):
Credential safety: Always pass API keys via environment variables, never as raw strings.
Keys are written to workspace .env (mode 0600) or ~/.config/lobster/credentials.env.
# Anthropic (most common)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Non-interactive init (agents can run this):
Credential safety: Always pass API keys via environment variables, never as raw strings.
Keys are written to workspace .env (mode 0600) or ~/.config/lobster/credentials.env.
# Anthropic (most common)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Non-interactive init (agents can run this):
Credential safety: Always pass API keys via environment variables, never as raw strings.
Keys are written to workspace .env (mode 0600) or ~/.config/lobster/credentials.env.
# Anthropic (most common)
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
| Flag | Purpose |
|------|---------|
| `--global` | Save to `~/.config/lobster/` instead of workspace — writes global config |
| `--force` | Overwrite existing config (creates timestamped backup first) |
| `--cloud-key <key>` | Omics-OS Cloud API key (premium tier) |
**Check if already configured**:
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
| `/session` | Current session info (ID, messages, data) |
| `/save [--force]` | Save all modalities to workspace |
| `/export [--no-png]` | Export session data + plots to `exports/` |
| `/clear` | Clear conversation history |
| `/reset` | Reset conversation (retains loaded data) |
| `/status` | Subscription tier, packages, agents |
| `/tokens` | Token usage and costs |
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
| `/save [--force]` | Save all modalities to workspace |
| `/export [--no-png]` | Export session data + plots to `exports/` |
| `/clear` | Clear conversation history |
| `/reset` | Reset conversation (retains loaded data) |
| `/status` | Subscription tier, packages, agents |
| `/tokens` | Token usage and costs |
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
lobster config show-config # Full runtime config lobster config create-custom # Interactive custom config lobster config models # Per-agent model config lobster config generate-env # Generate .env template
## Session Management
The manifest declares many generic trigger phrases such as "cluster," "run QC," "feature selection," and especially "bioinformatics," without narrowing context or giving exclusion conditions. Because this is a markdown/manifest file and the trigger scope is very broad, the skill could be invoked unintentionally during normal scientific or data-analysis discussion.
L164 states that only the Research Agent has internet access, yet the same file documents network-dependent behavior elsewhere, including on-demand docs fetches from docs.omics-os.com and provider API access for the platform. It also describes a Data Expert that performs dataset downloads and a Protein Structure Viz agent that fetches PDB data, which contradicts the absolute claim in the hard rule.
The document explicitly instructs agents to perform internet-backed literature and dataset searches, but it does not warn that prompts, search terms, and possibly dataset identifiers may be transmitted to external services. In a bioinformatics context, users may include unpublished study topics, patient-associated metadata, or sensitive research intent in queries, creating a real privacy and data-governance risk.
This markdown file documents lobster purge as removing Lobster files, but it does not include a clear user warning about the scope and impact of deleting local files. For markdown files, safety-relevant behaviors that may affect user data or system state should be accompanied by an explicit warning, especially when the command is destructive.
The /queue clear [type] command removes queue entries, which is a potentially destructive action affecting user workflow state. The markdown reference presents the command without any cautionary note about permanence or recoverability.
/metadata clear appears to remove metadata entries, which can alter or erase stored workspace/session state. The description does not include a caution about data loss or whether the action can be undone.
The document tells users to initialize the tool non-interactively using ANTHROPIC_API_KEY from the environment, but it does not include a warning that the skill accesses sensitive credentials during setup. Markdown guidance should disclose credential-sensitive behavior when it may affect user privacy or system integrity.
The /open <file> command launches the selected file in the system default app, which affects the local system and may invoke external applications. The reference lists the behavior but does not warn users that this will open software outside the CLI context.
/clear and /reset alter conversational state, and /clear in particular may remove context that users expect to retain. The reference describes the commands tersely without warning that session history or context may be lost.
No suspicious patterns detected.