Back to skill

Security audit

LobsterOps

Security checks for vulnerabilities and agentic risk

Overview

This is a real agent logging/debugging skill, but it records sensitive agent activity and its safeguards for redaction, storage protection, and log mutation are under-scoped.

Review this before installing in any environment where agent prompts, tool outputs, credentials, customer data, or proprietary context may be logged. Use local storage with restrictive filesystem permissions, avoid Supabase unless you have proper access controls, disable reasoning/tool-output capture unless needed, do not rely on the built-in PII filter as a secret scrubber, and treat CSV exports as unsafe to open in spreadsheets unless formula neutralization is added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/core/LobsterOps.js:104
Finding

PII Filtering Can Be Bypassed Through Event Options and Updates

Content
View full analysis
this.filter(item)); } if (typeof data === 'object') { const filtered = {}; for (const [key, value] of Object.entries(data)) { filtered[key] = this.filter(value); } return filtered; } return data; } ``` ### Technical Analysis `logEvent` filters only the original `event` object. It subsequently merges the caller-controlled `options` object after filtering, so values supplied through `options` are written to storage without passing through `PIIFilter`. The public `updateEvent` method also forwards the entire `updates` object directly to the selected storage backend without applying filtering. An event that was safe when initially recorded can therefore be modified to contain unredacted secrets. The ...[truncated 1850 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/storage/JsonFileStorage.js:24
Finding

Sensitive Local Telemetry Is Created Without Restrictive Filesystem Permissions

Content
View full analysis
{ this.db = new sqlite3.Database(this.filename, (err) => { if (err) { if (this.verbose) console.error('SQLite connection error:', err); ``` ```js // src/storage/SQLiteStorage.js:465-474 _ensureDirectory() { const dir = path.dirname(this.filename); if (dir && dir !== '.') { const fs = require('fs').promises; fs.mkdir(dir, { recursive: true }).catch(() => { // Ignore if directory already exists or we can't create it }); } } ``` ### Technical Analysis The JSON backend creates its data directory and event files without explicit permission modes. The SQLite backend similarly creates its directory and database using process defaults. Effective access therefore depends on the host's umask and any pre-existing directory permissions. LobsterOps intentionally records highly sensitive telemetry, including Agent thoughts, complete tool inputs and outputs, session identifiers, errors, and optional file or Git activity. Relying on ambient filesystem defaults is ...[truncated 1382 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/storage/SQLiteStorage.js:169
Finding

Unvalidated SQLite Sort Field Allows SQL Query Injection

Content
View full analysis
= ?'; params.push(startDate); } if (endDate) { whereClause += ' AND timestamp <= ?'; params.push(endDate); } if (eventTypes.length > 0) { const placeholders = eventTypes.map(() => '?').join(','); whereClause += ` AND type IN (${placeholders})`; params.push(...eventTypes); } if (agentIds.length > 0) { const placeholders = agentIds.map(() => '?').join(','); whereClause += ` AND agentId IN (${placeholders})`; params.push(...agentIds); } if (actions.length > 0) { const placeholders = actions.map(() => '?').join(','); whereClause += ` AND action IN (${placeholders})`; params.push(...actions); } // Build and execute query const query = ` SELECT * FROM lobsterops_events WHERE ${whereClause} ORDER BY ${sortBy} ${validSortOrder} LIMIT ? OFFSET ? `; params.push(limit, offset); const rows = await this._executeQuery(query, params); ``` ### Technical Analysis Filter values are parameterized ...[truncated 1882 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/core/Exporter.js:121
Finding

CSV Export Allows Spreadsheet Formula Injection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (34)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes a substantive observability and debugging tool for autonomous AI systems. However, the supplied code chunk does not implement any such functionality; it merely configures Jest test execution. While test configuration can be a supporting artifact in a larger project, this specific code chunk does not reflect the declared primary purpose and instead serves an unrelated development/testing role. Therefore, this is a description-behavior mismatch for the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description emphasizes observability and debugging/flight recording for AI systems, but the supplied code chunk's direct functionality is a privacy/sanitization component. It recursively scans data and replaces detected PII and secrets with a redaction token. While such filtering could be a supporting component within an observability tool, this specific chunk does not implement observability, logging, tracing, or a debug console. Its primary behavior is materially different from the declared purpose, so this code chunk is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: picomatch==2.3.1 — 2 advisory(ies): CVE-2026-33672 (Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Mat); CVE-2026-33671 (Picomatch has a ReDoS vulnerability via extglob quantifiers)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==1.1.12 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: browserslist==4.28.1 — 2 advisory(ies): CVE-2026-73088 (Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.); CVE-2026-73089 (Browserslist: Unbounded memory growth (no cache eviction) via distinct query res)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==5.0.4 — 5 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-45149 (brace-expansion: Large numeric range defeats documented `max` DoS protection) +2 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ip-address==10.1.0 — 2 advisory(ies): CVE-2026-69192 (ip-address: Address4 decodes leading-zero octets as decimal while resolvers deco); CVE-2026-42338 (ip-address has XSS in Address6 HTML-emitting methods)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · src/core/AlertManager.js (reported line 32)May include surrounding context.

js
enabled: rule.enabled !== false,
      createdAt: new Date().toISOString(),
    });
    return ruleId;
  }

  /**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README promotes capture of thoughts, reasoning traces, tool inputs/outputs, exports, and queryable history, but it does not prominently warn that these logs may contain secrets, personal data, proprietary prompts, or sensitive operational context. In an observability product for autonomous agents, users may enable broad instrumentation assuming the built-in PII filtering is sufficient, even though many sensitive artifacts are not reliably covered by regex-based redaction and may then be persisted, shared, or exported.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding

The skill declares environment variable usage and external-service configuration but does not define any explicit tool scope or permission boundary. In agent ecosystems, missing scope declarations can cause the skill to be invoked with broader-than-expected capabilities, increasing the chance of unintended access to secrets or external systems.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Broad trigger phrases like logging or showing what an agent did could match common user requests and activate the skill unexpectedly. In a logging/debug skill, unintended activation is risky because it may capture sensitive prompts, tool outputs, or operational metadata that the user did not intend to record or expose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The debug invocation is ambiguous about when the skill should engage, which can lead to accidental activation during ordinary troubleshooting requests. Given the skill's context as a flight recorder/debug console, accidental invocation could expose historical traces, internal reasoning artifacts, or sensitive event data beyond user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code file performs detailed inspection of agent trace events and returns full copies of event data, including tool inputs/outputs and agent thought content. Although the methods are documented for developers, there is no user-facing warning, confirmation, or visible disclosure that potentially sensitive trace data may be surfaced during inspection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code exposes a deletion operation that can remove events matching arbitrary criteria, but the method contains no confirmation prompt, visible logging, or cautionary comment/docstring warning about the destructive effect. Because this is a code file and deletion is a safety-relevant operation, the absence of any disclosure makes accidental or opaque data loss more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The cleanupOld method performs irreversible removal of historical events via the storage backend, but the code provides no user-facing notice, confirmation, or warning beyond a generic description. For destructive cleanup behavior in a code file, some form of disclosure is expected so users understand that stored observability data may be deleted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This instrumentation captures and forwards sensitive telemetry including tool inputs/outputs, reasoning traces, file-change metadata, and git-operation details, but this file provides no consent, notice, redaction, or policy gating before collection. In an observability skill for autonomous agents, these fields can contain secrets, proprietary code, personal data, or internal decision traces, so silent collection materially increases privacy and data-exfiltration risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The deleteEvents method removes matching events and overwrites the backing JSON files, which is an irreversible data-modifying operation. The file contains no confirmation prompt, user-visible log, or explicit warning indicating that matching stored events will be deleted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The cleanupOld method automatically deletes storage files older than maxAgeDays using fs.unlink, which is a destructive operation. Although the code comments describe the behavior for developers, there is no user-facing confirmation, logging, or other disclosure that persisted data will be removed automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The deleteEvents method removes matching in-memory events, including the possibility of deleting all events when called with an empty filter, but there is no confirmation prompt, logging, or user-facing disclosure in this file for this destructive action. Although the class comment explains data is non-persistent, it does not warn that stored events can be deleted programmatically in bulk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code performs irreversible deletion of stored events, and the default filter handling allows deletion across all records when no constraints are provided. Although the function is named deleteEvents, there is no confirmation prompt or stronger in-code warning beyond ordinary comments/docstrings to disclose the destructive behavior to downstream users of the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The cleanupOld method irreversibly removes historical events based on age, but the surrounding documentation does not clearly warn users that data will be permanently deleted. This is a safety-relevant operation affecting stored user/system data and should be disclosed plainly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes the skill as an 'AI Agent Observability & Debug Console - flight recorder and debug console,' which strongly suggests recording and inspecting agent events. This file also implements update and deletion capabilities for stored events, including bulk deletion and age-based cleanup, which go beyond passive observability and materially alter the historical record.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

For a flight-recorder/debug-console capability, querying and storing telemetry are expected, but arbitrary updateEvent, deleteEvents, and cleanupOld operations introduce mutation and removal of audit/debug data. Those capabilities can undermine the integrity of debugging history and are not obviously required by the stated purpose alone.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code performs bulk deletion of events in deleteEvents and irreversible cleanup in cleanupOld, but there is no confirmation prompt, logging, or explicit user-facing disclosure at the point of deletion. For a code file, destructive operations should have some visible warning unless the disclosure is provided elsewhere, and no such warning is evident in this file.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @babel/core==7.29.0 — 1 advisory(ies): CVE-2026-49356 (@babel/core: Arbitrary File Read via sourceMappingURL Comment)

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/storage/SupabaseStorage.js:20