Back to plugin

Security audit

Lobster

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent optional workflow plugin, but users should enable it only with tight tool allowlists because workflows can perform side-effecting actions.

Before installing, treat Lobster as a workflow execution tool: enable it only for agents that need it, configure a non-empty allowlist for tools it may invoke, and avoid running untrusted workflow files or pipelines because they may access the gateway environment and perform allowed side-effecting actions.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.