Back to skill

Security audit

Jules and the Lobster API headless

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed Jules API helper, but its bundled shell script can turn crafted task text into local Python code execution.

Review this skill before installing. Use it only with trusted task text until scripts/jules_api.sh is fixed to pass values to JSON encoding as data, not generated Python source. Keep JULES_API_KEY scoped and protected, limit Jules GitHub app access to intended repositories, and avoid --auto-pr or --no-plan-approval on sensitive repos.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/jules_api.sh:78
Finding

Shell-to-Python Code Injection Through Unsafe Heredoc Interpolation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior and declared purpose do not align with the detected capabilities, including mention of a local jules CLI wrapper and undeclared commands. Description-behavior mismatch is dangerous because reviewers and users may trust the manifest while the skill executes different paths, potentially bypassing expected authentication, logging, review, or data-flow assumptions.

Content

No source excerpt is available for this finding.

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 475)May include surrounding context.

md
# List activities for a session
./scripts/jules_api.sh activities --session <id> [--page-size N]

# Send message to session
./scripts/jules_api.sh send-message --session <id> --prompt "..."

# Approve plan

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares shell-capable behavior but does not constrain tool scope with explicit permissions or allowed-tools. In an agent environment, this broadens what the skill may invoke and increases the chance of unintended command execution or misuse beyond the documented Jules API interactions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

Retrieves a single source by name.

bash
curl -sS \
  -H "x-goog-api-key: $JULES_API_KEY" \
  "https://jules.googleapis.com/v1alpha/sources/github/octocat/Hello-World"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 331)May include surrounding context.

Retrieves a single session by ID.

bash
curl -sS \
  -H "x-goog-api-key: $JULES_API_KEY" \
  "https://jules.googleapis.com/v1alpha/sessions/SESSION_ID"

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The new command advertises --task but passes the supplied value to the underlying CLI as --session, changing the semantic meaning of user input. In a delegation/coding-agent context, this can cause actions to target an existing session or the wrong resource, leading to unintended execution flow, cross-session interference, or accidental disclosure/modification of another task's state.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a skill that uses the Jules REST API via curl to list sources, create sessions, monitor activities, approve plans, send messages, and retrieve outputs. This file instead shells out to a local jules CLI via spawnSync and only exposes version, list-repos, list-sessions, new, and pull, omitting several advertised API actions while introducing a different execution model.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The --auto-pr flag enables AUTO_CREATE_PR during session creation, which can cause external side effects in a connected repository. The script does not emit any warning or confirmation when this mode is enabled, beyond listing the flag in the usage examples.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code exposes a --no-plan-approval option that turns off plan approval for new sessions, which is a safety-relevant behavior change. Although the flag appears in usage text, the script provides no warning, confirmation, or explicit disclosure at the point of use that approvals are being bypassed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/jules_api.sh (reported line 65)May include surrounding context.

sh
case "$cmd" in
  sources)
    curl -sS "${BASE}/sources" "${hdr[@]}"
    ;;
  sessions)
    curl -sS "${BASE}/sessions?pageSize=${page_size}" "${hdr[@]}"

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest description at L003 scopes the skill to using the Jules REST API via curl, but the dependency list and later documentation introduce an additional wrapper around the Jules CLI. That is a distinct interaction mode not reflected in the stated description, even though it is presented as optional.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description lists listing sources, creating sessions, monitoring activities, approving plans, sending messages, and retrieving outputs, but does not mention deleting sessions. Documenting DELETE /sessions expands the skill's behavior beyond the declared set of operations.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/jules.js:17