Back to skill

Security audit

Prd

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly documentation for PRD planning, but it includes an unsafe autonomous coding-agent loop that disables permission checks and can keep making changes until manually stopped.

Review this skill carefully before installing. Its PRD templates are ordinary, but do not run the unattended Claude loop as written unless you deliberately accept unreviewed repository changes, quota use, and command execution in a tightly isolated environment. Prefer manual review, bounded iterations, normal permission prompts, and a disposable worktree or container.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/agent-usage.md:9
Finding

Unbounded Autonomous Agent Execution with Permission Checks Disabled

Content
View full analysis

Vulnerability Details

File Location: references/agent-usage.md, lines 9–12
Vulnerability Type: Permission bypass and unsafe unbounded automation
Risk Level: High

Vulnerable Code:

bash
while :; do
  claude --print --dangerously-skip-permissions \
    "Read prd.json, find first story where passes=false, implement it, run checks, update passes=true if successful"
done

Technical Analysis

The documented workflow combines an unconditional infinite shell loop (while :) with the --dangerously-skip-permissions option. This suppresses normal interactive authorization boundaries while directing an autonomous coding agent to read repository-controlled content, modify code, run quality checks, and update files.

Although the agent prompt defines work through prd.json, the workflow does not validate that file or constrain which commands may be executed during implementation and verification. Repository-controlled PRD entries, instruction files, source files, build scripts, test commands, or dependencies could therefore influence the agent's actions while approval checks are disabled.

The loop also fails to evaluate the documented completion condition. Even after all stories have passes: true, the shell continues launching new agent sessions. This can repeatedly consume CPU, API quota, and other resources, and may cause repeated or unintended repository operations.

The effective privileges are limited by the operating-system account, environment, credentials, network access, and tools available to the Claude CLI process. However, within those boundaries, the workflow intentionally removes the agent's normal permission prompts and therefore violates least-privilege principles.

Attack Path

  1. A user follows the documented instructions and starts the unattended loop.
  2. The Claude CLI runs with --dangerously-skip-permissions, removing interactive approval requirements.
  3. The agent reads `p ...[truncated 1457 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove --dangerously-skip-permissions and retain interactive approval for command execution, file access outside the repository, network operations, credential access, and destructive changes.
  2. Replace while : with a bounded loop that checks whether any incomplete stories remain before invoking the agent and exits immediately when all stories pass.
  3. Set a maximum iteration count, execution timeout, retry limit, and API-cost budget.
  4. Validate prd.json against a strict schema, including approved branch-name syntax, bounded story counts, expected field types, and rejection of command-like or instruction-injection content where possible.
  5. Treat all repository content as untrusted data. Explicitly instruct the execution agent not to follow repository instructions that expand scope, disable safeguards, access secrets, or override the initiating user's requirements.
  6. Run unattended agents inside an isolated container or restricted worktree under a dedicated low-privilege account. Mount only required project paths and avoid exposing home directories, SSH keys, cloud credentials, tokens, or production configuration.
  7. Restrict network access and use an allowlist for required services. Provide short-lived, narrowly scoped credentials only when necessary.
  8. Allowlist quality-check commands rather than permitting arbitrary commands inferred from repository content.
  9. Require human review before commits, migrations, dependency installation, external publication, or other security-sensitive operations.
  10. Log every command and changed file, and stop execution immediately when unexpected paths, commands, or repeated failures are detected.

A safer control flow should first query for an incomplete story, invoke the agent only when one exists, preserve permission prompts, and terminate after a defined number of attempts.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L003 states that the skill 'only edits PRDs', which describes a narrowly scoped behavior. However, the rest of the document instructs agents to implement stories, run checks, create or switch branches, commit code, and update progress files, which materially exceeds merely editing PRDs and directly contradicts the stated limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example runs claude --dangerously-skip-permissions inside an infinite unattended loop, which implies repeated autonomous actions without interactive approval. The surrounding text does not warn users that this bypasses permission checks or that the agent may modify the workspace continuously.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.