Back to skill

Security audit

mission-orchestrator

Security checks across malware telemetry and agentic risk

Overview

This lifecycle orchestration skill is mostly purpose-aligned, but it can create GitHub issues, persist project history, and reduce checkpoints from broad or casual directives in ways users should review before installing.

Install only if you want this skill to manage multi-phase project work and write .attune workflow state. Before using it, review or disable automatic GitHub issue creation, avoid broad --auto or casual autonomy directives on sensitive projects, and keep .attune files out of shared repositories if they may contain project history, errors, or review feedback.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
An orchestrator whose stated role is phase detection and routing should not silently expand into external side effects like creating GitHub issues unless that behavior is explicit, consented to, and tightly scoped. External issue creation can leak internal plans, generate unwanted artifacts in third-party systems, and be abused to spam or exfiltrate project context.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The module explicitly maps common natural-language phrases like 'I trust you' and 'go ahead' to weaker governance profiles, allowing checkpoint suppression and increased autonomy without a strong, explicit consent mechanism. In an orchestration skill, this is dangerous because routine conversational phrasing can be reinterpreted as authorization to reduce oversight, making social-engineering-triggered safety downgrades likely.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The manual override is documented to supersede both mission defaults and risk upgrades, which means a user or upstream prompt can force weaker controls even when the task has been classified as higher risk. In a lifecycle orchestrator, allowing overrides to defeat risk-based escalation undermines the purpose of adaptive safeguards and creates a straightforward path to under-governed execution.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
This section instructs the orchestrator to perform external side effects by running GitHub CLI commands and then modify local artifacts automatically based on parsed document content. Without explicit confirmation, sanitization, and permission boundaries, a crafted artifact could cause unintended issue creation, spam, or unsafe propagation of untrusted text into external systems and files.

Vague Triggers

High
Confidence
93% confidence
Finding
Broad triggers like "mission," "lifecycle," and "automation" can cause accidental invocation in unrelated contexts, especially because this skill can persist state, route work across multiple phases, and trigger external actions. Overbroad activation increases the chance of unintended autonomous behavior without informed user intent.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill describes backlog triage that may create GitHub issues but does not clearly warn users that orchestration can perform external side effects. Missing disclosure undermines informed consent and may cause sensitive internal content or premature plans to be posted to external repositories.

Missing User Warnings

Low
Confidence
76% confidence
Finding
Persisting mission state to `.attune/mission-state.json` is not inherently unsafe, but failing to clearly warn users can expose project metadata, workflow history, and potentially sensitive filenames or progress notes to disk unexpectedly. In shared or checked-in workspaces, that state may later be disclosed or misused.

Vague Triggers

High
Confidence
98% confidence
Finding
Broad substring matching on common conversational phrases creates an injection-like control channel where ordinary language can silently alter security posture. Because these phrases are easy to embed in user prompts or intermediary content, the skill becomes highly susceptible to social or prompt-based manipulation that disables checkpoints and reduces oversight.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The design allows automatic checkpoint skipping after detecting conversational directives, but only says the orchestrator should acknowledge the override once rather than requiring a clear warning and confirmation about the reduced governance. This weak transparency increases the chance that users unintentionally authorize unsafe execution paths and do not understand that oversight has been reduced.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The workflow describes automatic GitHub issue creation and artifact rewriting without a prominent warning or consent checkpoint for external network actions and file modifications. In an orchestration skill that may run in auto mode, this increases the risk of silent side effects, unauthorized repository changes, and accidental disclosure of sensitive project details to GitHub.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The module explicitly instructs the agent to persist a per-phase reflexion buffer containing actions, results, diagnoses, and adjustments into mission-state.json. In a project orchestration context, those fields can easily contain sensitive operational details, stack traces, file paths, secrets accidentally echoed in errors, or human-authored diagnoses, and the skill provides no consent, minimization, retention, or redaction guidance before storage.

Ssd 1

High
Confidence
95% confidence
Finding
Natural-language phrases such as "don't keep asking" and "be autonomous" are explicitly treated as overrides that relax safeguards and reduce approval checkpoints. This creates a prompt-injection-like control surface where casual wording or manipulated user text can lower operational friction for risky actions, increasing the chance of unauthorized or insufficiently reviewed behavior.

Ssd 4

Medium
Confidence
88% confidence
Finding
The workflow institutionalizes a pattern where trust signals progressively reduce scrutiny, which can normalize permission escalation over time. In an orchestration skill with multi-phase execution and possible external actions, this makes social engineering and accidental over-delegation more dangerous because reduced oversight becomes a built-in feature rather than an exception.

Ssd 1

High
Confidence
98% confidence
Finding
Treating trust-language as permission to suppress checkpoints turns rapport-building phrases into security-relevant commands. In a system that orchestrates project execution, this is dangerous because attackers or accidental wording can induce the agent to stop seeking review at the exact moments where oversight would catch mistakes or abuse.

Ssd 2

High
Confidence
97% confidence
Finding
The file explicitly enumerates paraphrases like 'don't ask' and 'be autonomous' as signals to auto-continue transitions and skip blocking gates, effectively codifying social-engineering phrases as bypass tokens. This materially lowers the barrier for prompt-level attacks and makes normal user conversation a vehicle for disabling safeguards.

Ssd 4

Medium
Confidence
88% confidence
Finding
By defining trust-building and autonomy-seeking language as governance-lowering directives, the workflow normalizes progressive relaxation of oversight through conversational framing. This increases operational risk over time because it teaches both users and downstream components that reduced scrutiny is an acceptable response to reassurance or urgency cues.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
demonstrated competence. Trust is earned slowly through
repeated success and lost quickly on failure. This
follows the Auto MoC principle: by batch four, 95% of
fixes ran without asking permission. Experienced users
increase both autonomy and strategic interruption
(Anthropic autonomy research).
Confidence
89% confidence
Finding
This skill explicitly defines a mechanism to reduce or skip user checkpoints based on prior success, culminating in T3 behavior that suppresses all intermediate approvals. In a workflow orchestrator, that creates a real autonomy-risk condition because mistakes, scope drift, or unsafe operations may proceed with limited human review, and the `--auto` flag further broadens this behavior across tiers.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.