LuLu CLI

Security checks across malware telemetry and agentic risk

Overview

This is a transparent LuLu firewall-management helper with powerful but disclosed sudo actions.

Install this only if you want an agent to help manage LuLu firewall rules. Review every `sudo lulu-cli` command before approving it, prefer narrow app/domain-specific rules over global wildcards, and verify the external Homebrew tap because the CLI binary is not part of the reviewed skill artifacts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes generic phrases such as "allow domain," "firewall rules," and "unblock," which can cause the skill to activate in broad, ambiguous situations. Because this skill grants access to privileged firewall-management commands, unintended invocation could lead an agent to change network policy when the user did not explicitly request it.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The reload command states there is an '~8 second gap in filtering during restart', which means firewall enforcement is temporarily reduced or absent. In a firewall-management skill focused on preventing data exfiltration, underemphasizing that protection gap could cause operators to reload at unsafe times and inadvertently allow unwanted outbound connections.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal