Back to skill

Security audit

war-room

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Review item because it can publish sensitive decision content externally, persist deliberation records, and launch delegated agents with permission safeguards disabled.

Install only after reviewing and changing defaults: make GitHub publishing explicit opt-in, remove permission-bypass GLM commands and persistent aliases, require confirmation before deferred capture or repository writes, and avoid using it for confidential decisions unless local retention and external sharing are understood.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
modules/expert-roles.md:45
Finding

External Expert Invocation Disables Permission Controls

Content
View full analysis
list[str]: """ Resolve GLM-4.7 invocation command with fallback. Priority: 1. ccgd (alias) - if available in PATH 2. claude-glm --dangerously-skip-permissions - explicit fallback 3. ~/.local/bin/claude-glm - direct path fallback """ import shutil from pathlib import Path # Check for alias if shutil.which("ccgd"): return ["ccgd", "-p"] # Check for script in PATH if shutil.which("claude-glm"): return ["claude-glm", "--dangerously-skip-permissions", "-p"] # Direct path fallback local_bin = Path.home() / ".local" / "bin" / "claude-glm" if local_bin.exists(): return [str(local_bin), "--dangerously-skip-permissions", "-p"] raise RuntimeError( "GLM-4.7 not available. Install claude-glm or configure ccgd alias.\n" "Add to ~/.bashrc: alias ccgd='claude-glm --dangerously-skip-permissions'" ) ``` The same unsafe invocation is also explicitly advertised in `SKILL.md:154-158`: ```markdown ### With Conjure Experts are invoked via conjure delegation: - `conjure:gemini-delegation` for Gemini models - `conjure:qwen-delegation` for Qwen models - Direct CLI for GLM-4.7 (`ccgd` or `claude-glm --dangerously-skip-permissions`) ``` ### Technical Analysis The `--dangerously-skip-permissions` option intentionally bypasses the ...[truncated 2041 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:405
Finding

Sensitive Deliberation Content Is Published Externally by Default

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger set includes broad terms like 'strategy', 'decision-making', and 'deliberation', which can cause the skill to activate in many ordinary contexts. In this skill, overbroad activation is more dangerous because activation can lead to persistence, subprocess spawning, and optional remote publication, magnifying the consequences of accidental routing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that sessions persist to the Strategeion but does not clearly warn that user content and decision artifacts are saved by default. For a strategy and deliberation tool, stored artifacts may include sensitive architectural, business, or security discussions, so silent persistence materially increases confidentiality and privacy risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s stated purpose is deliberation support, but it additionally requires GitHub Discussion publishing and updates local state, creating external side effects beyond what a user would reasonably infer from the manifest. This increases the risk of unintended data disclosure, repository modification, and persistence of sensitive decision content without sufficiently explicit consent or scoping.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Directing the agent to execute gh api graphql commands to create Discussions and post threaded comments is an operational action unrelated to core deliberation, and it can exfiltrate sensitive decision details to a remote platform. Because the workflow is framed as required by default, users may not realize that strategic or internal content will be published externally.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes the skill as convening a multi-LLM expert panel to pressure-test hard-to-reverse decisions. This file instructs the agent to persist rejected COAs and dissenting-view items via an external capture script after the decision is finalized, which is a post-decision archival/integration workflow rather than part of convening or running the panel itself.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module instructs automatic execution of an external script with interpolated values such as title, context, artifact path, and session ID. Even though the command is presented as a template, coupling the skill to a repository script creates a write-side effect and potential abuse path if inputs are attacker-controlled, the script is unsafe, or the repository contains a trojanized implementation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The directive 'do not prompt the user' is a clear autonomous-decision pattern that bypasses operator consent for an action that persists data. In a deliberation assistant, this is more dangerous because the expected function is advisory analysis, not unsupervised execution of follow-on actions affecting repository or session state.

Content

Scanner excerpt · modules/deferred-capture.md (reported line 60)May include surrounding context.

md
## Behavior Rules

- Capture is automatic: do not prompt the user for
  confirmation.
- Capture every qualifying COA in a single pass before
  closing the session.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Mandating automatic capture without confirmation removes a human checkpoint before performing repository write actions. In this context, the skill is supposed to facilitate deliberation, so autonomous persistence of records increases the risk of unintended data creation, capture of sensitive discussion content, or unauthorized state changes if triggered inappropriately.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The protocol explicitly states that sessions are persisted after each phase and can be resumed, but it does not warn users that deliberation artifacts, prompts, context files, and possibly sensitive strategic content may be stored. In a multi-LLM decision-making skill, these artifacts are likely to contain confidential business, operational, or personal information, so silent persistence increases the risk of unintended retention, later disclosure, or use beyond user expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Agent Teams section describes spawning persistent teammate processes, inbox messaging, retained context across rounds, and tmux pane cleanup, but does not clearly disclose to users that background agent sessions may continue operating and holding context during the deliberation. This is risky because users may not realize additional long-lived processes are being created, that more data is being shared across agents, or that failure to shut down cleanly could leave active sessions or residual artifacts behind.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module defaults to publishing deliberation output to GitHub Discussions and includes rich session content such as context, rationale, consequences, reversibility analysis, expert panel details, session IDs, and local file paths, but it does not require an explicit sensitivity review or warning before external publication. In a decision-support skill, these artifacts can easily contain confidential strategy, internal architecture, security reasoning, or operational metadata, so default publication creates a real risk of unintended disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The configuration hard-codes a fallback command that includes --dangerously-skip-permissions, explicitly disabling permission safeguards for an external model invocation. In a deliberation-oriented skill, this broadens the authority of spawned tooling without clear necessity, increasing the blast radius if prompts, delegated tasks, or surrounding orchestration are influenced by untrusted input.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation presents dangerous permission-skipping commands as part of normal setup and fallback behavior without prominent warnings, constraints, or justification. Even if no code executes from the document itself, this can lead users to adopt unsafe operational practices that disable important safeguards across future runs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The GLM command resolver prefers or falls back to invocations that disable permission protections, and even instructs users to create a persistent alias for that unsafe mode. This is dangerous because it normalizes privileged execution for routine expert-panel use, making accidental overreach or abuse by downstream delegated actions much more likely.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The recommendation to add an alias to ~/.bashrc creates persistent session-level behavior that normalizes claude-glm --dangerously-skip-permissions for future use. Persistence increases risk because a one-time troubleshooting shortcut becomes the default execution path across sessions, making unsafe elevated behavior easy to trigger unintentionally.

Content

Scanner excerpt · modules/expert-roles.md (reported line 182)May include surrounding context.

raise RuntimeError( "GLM-4.7 not available. Install claude-glm or configure ccgd alias.\n" "Add to ~/.bashrc: alias ccgd='claude-glm --dangerously-skip-permissions'" )

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module explicitly supports reversing anonymization via unseal() and presenting full attribution, but it does not describe any consent, authorization, purpose limitation, or user warning before exposing identities that were previously masked. In a war-room deliberation context, attribution may reveal sensitive role/model metadata and chill candid participation; if invoked inappropriately, it creates a privacy and governance risk even if no code execution issue is present.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest frames the skill as a multi-LLM panel for decision pressure-testing, which can justify model delegation. But requiring Claude Code Agent Teams, experimental flags, and tmux-backed persistent teammates introduces process-orchestration capabilities not stated in the manifest and not obviously necessary from the description alone.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file instructs the skill to perform GitHub search and fetch prior discussion content, including body and answer fields, before the user explicitly chooses whether to review prior decisions. Because this is a network operation against repository data, a brief disclosure would improve transparency about external access and retrieval of discussion contents.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file describes when a role is active using broad phrases like "Always active for plan reviews" and "Optional for other war-room sessions" without clearly defining the boundaries of those session types. The lack of explicit inclusion/exclusion examples could lead to unintended or inconsistent invocation of the role.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.