Back to skill

Security audit

Coil API

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for operating Coil, but it asks users to globally install an unverified CLI that will handle organization credentials, provider secrets, cookies, and lead data.

Install only if you trust the Coil npm package publisher and are comfortable granting the CLI access to your Coil organization data, provider tokens, LinkedIn cookie, lead records, exports, and automation workflows. Prefer a sandboxed or project-local install, use scoped/rotatable secrets, and review server-returned human-action URLs before taking admin actions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:39
Finding

Unaudited Third-Party CLI Is Installed Globally and Entrusted with Sensitive Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 39–43 and 100–105
Vulnerability Type: Supply-chain exposure through a globally installed third-party executable
Risk Level: Medium

Vulnerable Code

bash
if ! command -v coil >/dev/null 2>&1; then
  npm install --global @usecoil/cli@0.1.4
fi
coil --version

The installation is repeated in the runtime setup:

bash
npm install --global @usecoil/cli@0.1.4
coil config set-base-url https://www.usecoil.com --profile prod
printf '%s' "$COIL_API_KEY" | coil auth login --profile prod --key -
coil --profile prod agent-context --json

Technical Analysis

The Skill instructs the agent to download and globally install @usecoil/cli@0.1.4 from npm, then supplies the resulting executable with an organization API key and uses it for provider integrations, LinkedIn-backed scraping, lead management, and outbound automation.

Pinning an exact version reduces exposure to unexpected upgrades, but the project does not include the dependency's source, an integrity hash, a lockfile, a cryptographic signature, or another mechanism by which the downloaded artifact can be verified against audited code. Its effective behavior is therefore outside the reviewed project.

A global npm installation may execute package lifecycle scripts and places an executable into a shared command path. If the npm publication, maintainer account, registry delivery path, or referenced package version is compromised, attacker-controlled code could execute with the installing user's privileges. The installed CLI would also be in a position to read secrets deliberately passed over stdin and all business data processed through later commands.

Attack Path

  1. An attacker compromises the npm package publication process, its maintainer account, registry infrastructure, or the artifact associated with @usecoil/cli@0.1.4.
  2. The user or agent follows the Skill and runs the ...[truncated 1584 chars]
Remediation
View remediation

Remediation Suggestions

  1. Publish auditable source corresponding exactly to the supported CLI release.
  2. Distribute signed release artifacts and verify their cryptographic signatures or documented SHA-256 hashes before execution.
  3. Avoid global installation. Prefer a project-local, locked dependency or a verified standalone binary in a dedicated directory.
  4. Disable npm lifecycle scripts where feasible, such as with --ignore-scripts, after confirming that the package does not legitimately require them.
  5. Use a lockfile and registry integrity metadata when installing through npm.
  6. Run the CLI in a sandbox with restricted filesystem access, a minimal environment, and network access limited to approved Coil and provider endpoints.
  7. Continue passing secrets through stdin or a runtime secret manager rather than command-line arguments.
  8. Use narrowly scoped, short-lived credentials where supported, and rotate them after suspected dependency compromise.
  9. Document the expected package publisher, checksum, signing identity, and authorized network destinations so installations can fail closed on mismatch.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 322)May include surrounding context.

md
- `references/api-endpoints.md`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

md
- `references/api-fields.md`

Static analysis

No suspicious patterns detected.