T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned External CLI Installation Permits Supply-Chain Payload Changes
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly transparent about using ordercli, but it asks users to install a mutable external CLI and import browser sessions while also enabling cart-changing actions.
Review this skill carefully before installing. Prefer a pinned and verified ordercli version, avoid importing from your main Chrome profile, use a dedicated browser profile if browser login is necessary, and only run reorder commands when you explicitly want cart changes.
SKILL.md:5Unpinned External CLI Installation Permits Supply-Chain Payload Changes
SKILL.md:30Default Browser Profile Access Exposes Sensitive Authentication State
The manifest and description present the skill as a read-only order lookup tool, but the documented commands include reorder ... --confirm and cart-changing actions. This mismatch can mislead users and higher-level agents into invoking state-changing operations they did not authorize, creating an integrity and unintended-purchase risk.
The skill metadata says it is 'Foodora-only', but the documentation includes Deliveroo commands and references Deliveroo bearer tokens and cookies. This capability mismatch can cause agents or users to grant broader trust, credentials, or permissions than intended, increasing the risk of misuse or accidental handling of additional sensitive tokens.
The skill documents importing Chrome cookies and browser session data (cookies chrome, session chrome) to authenticate without a password. In an agent skill context, browser cookie and session extraction is highly sensitive because it can enable account takeover if misused, and the surrounding 'bot protection' framing normalizes bypass-style credential reuse from local browser profiles.
Cloudflare / bot protection
- Browser login: `ordercli foodora login --email you@example.com --password-stdin --browser`
- Reuse profile: `--browser-profile "$HOME/Library/Application Support/ordercli/browser-profile"`
- Import Chrome cookies: `ordercli foodora cookies chrome --profile "Default"`
Session import (no password)
- `ordercli foodora session chrome --url https://www.foodora.at/ --profile "Default"`
No suspicious patterns detected.