Back to skill

Security audit

Ordercli

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent about using ordercli, but it asks users to install a mutable external CLI and import browser sessions while also enabling cart-changing actions.

Review this skill carefully before installing. Prefer a pinned and verified ordercli version, avoid importing from your main Chrome profile, use a dedicated browser profile if browser login is necessary, and only run reorder commands when you explicitly want cart changes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:5
Finding

Unpinned External CLI Installation Permits Supply-Chain Payload Changes

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:30
Finding

Default Browser Profile Access Exposes Sensitive Authentication State

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest and description present the skill as a read-only order lookup tool, but the documented commands include reorder ... --confirm and cart-changing actions. This mismatch can mislead users and higher-level agents into invoking state-changing operations they did not authorize, creating an integrity and unintended-purchase risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill metadata says it is 'Foodora-only', but the documentation includes Deliveroo commands and references Deliveroo bearer tokens and cookies. This capability mismatch can cause agents or users to grant broader trust, credentials, or permissions than intended, increasing the risk of misuse or accidental handling of additional sensitive tokens.

Content

No source excerpt is available for this finding.

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
78% confidence
Finding

The skill documents importing Chrome cookies and browser session data (cookies chrome, session chrome) to authenticate without a password. In an agent skill context, browser cookie and session extraction is highly sensitive because it can enable account takeover if misused, and the surrounding 'bot protection' framing normalizes bypass-style credential reuse from local browser profiles.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
Cloudflare / bot protection
- Browser login: `ordercli foodora login --email you@example.com --password-stdin --browser`
- Reuse profile: `--browser-profile "$HOME/Library/Application Support/ordercli/browser-profile"`
- Import Chrome cookies: `ordercli foodora cookies chrome --profile "Default"`

Session import (no password)
- `ordercli foodora session chrome --url https://www.foodora.at/ --profile "Default"`

Static analysis

No suspicious patterns detected.