Back to skill

Security audit

Food Order

Security checks for vulnerabilities and agentic risk

Overview

This Foodora ordering skill is coherent and includes confirmation safeguards, but it installs a mutable third-party CLI that handles account sessions and can place purchases.

Review this before installing. Use it only if you trust the ordercli publisher and are comfortable giving that CLI access to your Foodora account or browser session. Prefer a pinned, reviewed ordercli version if available, confirm every order preview carefully, and avoid invoking the skill from vague requests like 'order food' unless you intend to use Foodora.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Security-Sensitive Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

yaml
metadata: {"clawdbot":{"emoji":"🥡","requires":{"bins":["ordercli"]},"install":[{"id":"go","kind":"go","module":"github.com/steipete/ordercli/cmd/ordercli@latest","bins":["ordercli"],"label":"Install ordercli (go)"}]}}

Technical Analysis

The installation metadata retrieves ordercli from a third-party Go module using the mutable @latest version selector. Consequently, installation can resolve to code that differs from the version reviewed during this audit.

This CLI is security-sensitive because the documented workflow grants it access to Foodora credentials or an authenticated browser session. It can also inspect order history and place purchases. Although no malicious behavior was found in the audited SKILL.md, the dependency is not included in the project and its future contents cannot be established from this artifact.

Attack Path

  1. An attacker compromises the upstream repository, maintainer account, release process, or another relevant supply-chain component.
  2. The attacker publishes a malicious version that becomes the version resolved by @latest.
  3. A user or agent installs the Skill dependency according to the metadata.
  4. The malicious ordercli executable runs when the documented Foodora commands are invoked.
  5. During login or session import, the executable may capture Foodora credentials or authenticated session material.
  6. It may then abuse account access, alter ordering operations, or execute arbitrary actions with the privileges of the user running the CLI.

Impact Assessment

Successful exploitation could execute attacker-controlled code under the installing user's operating-system privileges. Within the declared workflow, it could expose Foodora passwords or authenticated session data, disclose account and order information, and perfor ...[truncated 156 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace @latest with a specific, reviewed release version or immutable commit.
  • Establish a controlled dependency-update process that includes source review and security testing before changing the pinned version.
  • Verify release provenance and integrity where supported, and retain expected checksums or equivalent verification data.
  • Prefer reproducible installation mechanisms that fail closed when the expected artifact cannot be verified.
  • Run the CLI with the minimum necessary operating-system and account privileges.
  • Avoid exposing credentials through command-line arguments; continue using standard input or a narrowly scoped authentication mechanism.
  • Revoke Foodora sessions and investigate account activity if dependency compromise is suspected.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The trigger phrases include very broad language such as 'order food' and 'reorder', which can easily match ordinary conversation and invoke a skill capable of initiating commercial actions. Even though the skill text includes confirmation safeguards, accidental activation in the wrong context could still expose order history, prompt login flows, or pressure the user toward an unintended purchase.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.