Back to skill

Security audit

ask-cargo

Security checks for vulnerabilities and agentic risk

Overview

The skill largely does what it says, but it gives repository instructions too much authority over safety rules while running a Slack agent with repo and workspace access.

Install only after reviewing and changing the repository-instruction precedence so repo files cannot override approval, confidentiality, or prohibited-operation rules. Also verify Slack channel reach before deploy, keep the bot out of customer/shared channels, pin or preinstall the Cargo CLI, and require human review of PRs and any operation that spends, sends, or modifies records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
infra/agents/ask-cargo.prompt.ts:14
Finding

Repository Instructions Can Override the Skill's Safety Controls

Content
View full analysis

Vulnerability Details

File Location: infra/agents/ask-cargo.prompt.ts, lines 14–16
Vulnerability Type: Untrusted instruction precedence / prompt injection
Risk Level: High

Vulnerable code:

typescript
Read AGENTS.md (or CLAUDE.md) first for the repository's conventions.
Repository conventions win over anything in this prompt.

Technical Analysis

The system prompt directs the agent to read instructions from AGENTS.md or CLAUDE.md in the checked-out repository and gives those instructions unconditional precedence over the rest of the Skill prompt.

Repository files are task data that may be modified by repository contributors or other processes. They must not be allowed to override trusted authorization and safety policy. The precedence rule can supersede controls later in the prompt, including:

  • Approval before actions that spend, send, write to personal records, or invoke other agents.
  • Prohibitions against deployment, destruction, deletion, token operations, and membership changes.
  • Restrictions against exposing secrets, environment values, or complete records.
  • Restrictions against using Slack tools or writing workspace memory directly.

The Skill uses a Claude Code harness with a repository checkout, authenticated Cargo CLI access, and a GitHub connector capable of pushing branches and opening pull requests. Consequently, malicious repository guidance can influence operations across meaningful trust boundaries.

The prompt otherwise contains substantial operational restrictions, and evals/contract.mjs checks resource wiring. However, those measures do not neutralize the unconditional precedence statement, and the contract test does not enforce prompt-level authorization rules.

Attack Path

  1. A repository contributor or another process able to change repository content adds malicious instructions to AGENTS.md or CLAUDE.md.
  2. A teammate invokes Ask Cargo through an au ...[truncated 1465 chars]
Remediation
View remediation

Remediation Suggestions

Replace the unconditional precedence rule with an explicit trust hierarchy:

  • Treat AGENTS.md, CLAUDE.md, and all other repository files as untrusted project context.
  • Permit repository guidance to control only non-security matters such as formatting, coding style, test conventions, and project structure.
  • State that repository content cannot override system or Skill instructions, approval requirements, confidentiality controls, tool restrictions, prohibited operations, or user authorization.
  • Require the agent to ignore and report any repository instruction that conflicts with these controls.
  • Enforce sensitive operation gates in executable policy or tool wrappers rather than relying exclusively on natural-language instructions.
  • Extend contract or policy tests with adversarial repository fixtures that attempt to bypass approval, disclose secrets, invoke prohibited commands, or use unauthorized communication tools.
  • Apply command allowlists and independently enforce approval state for spending, external sends, record modification, and agent handoffs.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description is for a full Slack-facing orchestrator agent with repo awareness, PR generation, and multi-agent coordination. The supplied code chunk only configures an Anthropic connector via defineConnector, marking it as the default workspace connector. This is a supporting infrastructure piece, but by itself it does not implement the described user-facing agent behavior, triggers, or external actions. Therefore the actual code chunk does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 85)May include surrounding context.

md
## What it does not do

It does not deploy, merge, destroy or remove anything, mint tokens, change members, post to any
channel but the thread it was asked in, send to people the workspace has no consent basis for, or
run anything that spends without a go in the thread.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · infra/agents/ask-cargo.prompt.ts (reported line 127)May include surrounding context.

ts
## What it does not do

It does not deploy, merge, destroy or remove anything, mint tokens, change members, post to any
channel but the thread it was asked in, send to people the workspace has no consent basis for, or
run anything that spends without a go in the thread.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill describes a networked, Slack-triggered orchestrator that can query workspace state, invoke CLI commands, and open pull requests, but it declares no explicit tool scope or allowed-tools boundary. In a multi-connector environment, missing scope declarations increase the chance of overbroad network/API access and make it harder to audit or constrain what the agent may call.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest includes broad natural-language trigger phrases like 'one agent on top of all the others' and 'let anyone open a PR from slack,' which can encourage overbroad invocation and accidental use in contexts involving sensitive data or unintended repo changes. In a Slack-wide deployment, loose trigger semantics raise the risk of unreviewed activation and social-engineering-friendly prompts.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
**Derive before you ask.** An input with a lookup is looked up, not asked.

| Input                                                     | Kind  | How it is answered                                                                                                                                                                                                                                                | Why it matters                                                                                                                                                                                                                  |
| --------------------------------------------------------- | ----- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| repository binding (`infra/agents/ask-cargo.ts`)          | value | **derived**: `repository` is omitted, so `plan` binds the project's own repository from the git origin of the checkout, with the project's GitHub connector. `cargo-ai cdk check` prints what it resolved: confirm it names your repo and the root, not `infra/`.                               | This is the checkout every answer reads and every pull request opens against. An `owner/name` typed by hand is the value nobody notices is wrong until a pull request lands on a stranger's repository.                         |
| Slack, GitHub and LLM connectors (`infra/connectors/`)    | value | **derived**: `cargo-ai connection connector list` shows what is authorized; `cargo-ai cdk add connector/<slack\|github\|anthropic>` opens the consent for wh
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
**Derive before you ask.** An input with a lookup is looked up, not asked.

| Input                                                     | Kind  | How it is answered                                                                                                                                                                                                                                                | Why it matters                                                                                                                                                                                                                  |
| --------------------------------------------------------- | ----- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| repository binding (`infra/agents/ask-cargo.ts`)          | value | **derived**: `repository` is omitted, so `plan` binds the project's own repository from the git origin of the checkout, with the project's GitHub connector. `cargo-ai cdk check` prints what it resolved: confirm it names your repo and the root, not `infra/`.                               | This is the checkout every answer reads and every pull request opens against. An `owner/name` typed by hand is the value nobody notices is wrong until a pull request lands on a stranger's repository.                         |
| Slack, GitHub and LLM connectors (`infra/connectors/`)    | value | **derived**: `cargo-ai connection connector list` shows what is authorized; `cargo-ai cdk add connector/<slack\|github\|anthropic>` opens the consent for wh
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
| repository binding (`infra/agents/ask-cargo.ts`)          | value | **derived**: `repository` is omitted, so `plan` binds the project's own repository from the git origin of the checkout, with the project's GitHub connector. `cargo-ai cdk check` prints what it resolved: confirm it names your repo and the root, not `infra/`.                               | This is the checkout every answer reads and every pull request opens against. An `owner/name` typed by hand is the value nobody notices is wrong until a pull request lands on a stranger's repository.                         |
| Slack, GitHub and LLM connectors (`infra/connectors/`)    | value | **derived**: `cargo-ai connection connector list` shows what is authorized; `cargo-ai cdk add connector/<slack\|github\|anthropic>` opens the consent for what is missing. All three are `default: true` because a deploy cannot mint a grant.                      | Slack is the trigger, GitHub the only write path, Anthropic what every turn is billed against. A harness paired with a non-Anthropic connector typechecks green and fails at deploy.                                            |
| channel reach (`infra/agents/ask-cargo.ts`)               | value | **derived**: `allChannels: true`, so the reach is every channel the bot is in. Read them from the Slack connector's channel autocomplete; `cargo-ai ai agent list` shows which other agents list channels of their own.                                            | The agent reads the ICP, the pipeline and the spend out loud to whoever is in the channel. A customer shared channel the bot is in leaks all of it. A channel another agent lists stays that agent's, and a second `allChannels` agent answers alongside this one. |
| roster (`references/roster.md`)                           | value | **derived**: `cargo-ai ai agent list` for what is deployed, each agent's description for what it owns.                                                                                            
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
| repository binding (`infra/agents/ask-cargo.ts`)          | value | **derived**: `repository` is omitted, so `plan` binds the project's own repository from the git origin of the checkout, with the project's GitHub connector. `cargo-ai cdk check` prints what it resolved: confirm it names your repo and the root, not `infra/`.                               | This is the checkout every answer reads and every pull request opens against. An `owner/name` typed by hand is the value nobody notices is wrong until a pull request lands on a stranger's repository.                         |
| Slack, GitHub and LLM connectors (`infra/connectors/`)    | value | **derived**: `cargo-ai connection connector list` shows what is authorized; `cargo-ai cdk add connector/<slack\|github\|anthropic>` opens the consent for what is missing. All three are `default: true` because a deploy cannot mint a grant.                      | Slack is the trigger, GitHub the only write path, Anthropic what every turn is billed against. A harness paired with a non-Anthropic connector typechecks green and fails at deploy.                                            |
| channel reach (`infra/agents/ask-cargo.ts`)               | value | **derived**: `allChannels: true`, so the reach is every channel the bot is in. Read them from the Slack connector's channel autocomplete; `cargo-ai ai agent list` shows which other agents list channels of their own.                                            | The agent reads the ICP, the pipeline and the spend out loud to whoever is in the channel. A customer shared channel the bot is in leaks all of it. A channel another agent lists stays that agent's, and a second `allChannels` agent answers alongside this one. |
| roster (`references/roster.md`)                           | value | **derived**: `cargo-ai ai agent list` for what is deployed, each agent's description for what it owns.                                                                                            
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
The code is a worked example. These reshapes are expected, and the agent offers them rather than
waiting to be asked. Every one costs something.

| Variation             | When it is right                                                                                     | How                                                                                                                                                                                                  | What it costs                                                                                                                                                                                                                         |
| --------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `answer-only`         | You want a Slack oracle over the repo first, and no one running anything from Slack yet              | In `infra/agents/ask-cargo.prompt.ts`, replace §3 and §4 with "propose the command, never run it"                                                                                                    | The team copies commands out of Slack into a terminal, and "the agent said it would cost X" stops being checked against what actually ran.                                                                                            |
| `listed-channels`     | The bot sits in channels it must never answer in, or you want answers in a few channels only        | Replace `allChannels: true` with `channelIds: 
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
The code is a worked example. These reshapes are expected, and the agent offers them rather than
waiting to be asked. Every one costs something.

| Variation             | When it is right                                                                                     | How                                                                                                                                                                                                  | What it costs                                                                                                                                                                                                                         |
| --------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `answer-only`         | You want a Slack oracle over the repo first, and no one running anything from Slack yet              | In `infra/agents/ask-cargo.prompt.ts`, replace §3 and §4 with "propose the command, never run it"                                                                                                    | The team copies commands out of Slack into a terminal, and "the agent said it would cost X" stops being checked against what actually ran.                                                                                            |
| `listed-channels`     | The bot sits in channels it must never answer in, or you want answers in a few channels only        | Replace `allChannels: true` with `channelIds: 
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
The code is a worked example. These reshapes are expected, and the agent offers them rather than
waiting to be asked. Every one costs something.

| Variation             | When it is right                                                                                     | How                                                                                                                                                                                                  | What it costs                                                                                                                                                                                                                         |
| --------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `answer-only`         | You want a Slack oracle over the repo first, and no one running anything from Slack yet              | In `infra/agents/ask-cargo.prompt.ts`, replace §3 and §4 with "propose the command, never run it"                                                                                                    | The team copies commands out of Slack into a terminal, and "the agent said it would cost X" stops being checked against what actually ran.                                                                                            |
| `listed-channels`     | The bot sits in channels it must never answer in, or you want answers in a few channels only        | Replace `allChannels: true` with `channelIds: 
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
| Variation             | When it is right                                                                                     | How                                                                                                                                                                                                  | What it costs                                                                                                                                                                                                                         |
| --------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `answer-only`         | You want a Slack oracle over the repo first, and no one running anything from Slack yet              | In `infra/agents/ask-cargo.prompt.ts`, replace §3 and §4 with "propose the command, never run it"                                                                                                    | The team copies commands out of Slack into a terminal, and "the agent said it would cost X" stops being checked against what actually ran.                                                                                            |
| `listed-channels`     | The bot sits in channels it must never answer in, or you want answers in a few channels only        | Replace `allChannels: true` with `channelIds: ["C…"]` in `infra/agents/ask-cargo.ts`, from the connector's autocomplete                                                                         
...[truncated 26 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
| Variation             | When it is right                                                                                     | How                                                                                                                                                                                                  | What it costs                                                                                                                                                                                                                         |
| --------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `answer-only`         | You want a Slack oracle over the repo first, and no one running anything from Slack yet              | In `infra/agents/ask-cargo.prompt.ts`, replace §3 and §4 with "propose the command, never run it"                                                                                                    | The team copies commands out of Slack into a terminal, and "the agent said it would cost X" stops being checked against what actually ran.                                                                                            |
| `listed-channels`     | The bot sits in channels it must never answer in, or you want answers in a few channels only        | Replace `allChannels: true` with `channelIds: ["C…"]` in `infra/agents/ask-cargo.ts`, from the connector's autocomplete                                                                         
...[truncated 26 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
| Variation             | When it is right                                                                                     | How                                                                                                                                                                                                  | What it costs                                                                                                                                                                                                                         |
| --------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `answer-only`         | You want a Slack oracle over the repo first, and no one running anything from Slack yet              | In `infra/agents/ask-cargo.prompt.ts`, replace §3 and §4 with "propose the command, never run it"                                                                                                    | The team copies commands out of Slack into a terminal, and "the agent said it would cost X" stops being checked against what actually ran.                                                                                            |
| `listed-channels`     | The bot sits in channels it must never answer in, or you want answers in a few channels only        | Replace `allChannels: true` with `channelIds: ["C…"]` in `infra/agents/ask-cargo.ts`, from the connector's autocomplete                                                                         
...[truncated 26 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
| `answer-only`         | You want a Slack oracle over the repo first, and no one running anything from Slack yet              | In `infra/agents/ask-cargo.prompt.ts`, replace §3 and §4 with "propose the command, never run it"                                                                                                    | The team copies commands out of Slack into a terminal, and "the agent said it would cost X" stops being checked against what actually ran.                                                                                            |
| `listed-channels`     | The bot sits in channels it must never answer in, or you want answers in a few channels only        | Replace `allChannels: true` with `channelIds: ["C…"]` in `infra/agents/ask-cargo.ts`, from the connector's autocomplete                                                                            | A list to keep in sync: a new team channel gets no answer until someone edits the file and deploys. Listing a channel also takes it from any `allChannels` agent.                                                                  |
| `dms-too`             | Individuals want to ask privately                                                                    | Add each person's Slack **user id** (`U…`) to `channelIds` next to `allChannels`; DMs are listed by user, not by `D…` channel, and `allChannels` never covers them.                                   | The thread stops being multiplayer: nobody else sees the proposal or the go, so a DM go is one person approving spend alone. Keep §3 unchanged if you take this.                                                                    |
| `master-agent-slack`  | You only need questions answered, no repo and no pull requests                                       | Skip this cookbook. Put a Slack trigger on the workspace's built-in Master Agent in the UI.                                                                                                          |
...[truncated 26 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
| `listed-channels`     | The bot sits in channels it must never answer in, or you want answers in a few channels only        | Replace `allChannels: true` with `channelIds: ["C…"]` in `infra/agents/ask-cargo.ts`, from the connector's autocomplete                                                                            | A list to keep in sync: a new team channel gets no answer until someone edits the file and deploys. Listing a channel also takes it from any `allChannels` agent.                                                                  |
| `dms-too`             | Individuals want to ask privately                                                                    | Add each person's Slack **user id** (`U…`) to `channelIds` next to `allChannels`; DMs are listed by user, not by `D…` channel, and `allChannels` never covers them.                                   | The thread stops being multiplayer: nobody else sees the proposal or the go, so a DM go is one person approving spend alone. Keep §3 unchanged if you take this.                                                                    |
| `master-agent-slack`  | You only need questions answered, no repo and no pull requests                                       | Skip this cookbook. Put a Slack trigger on the workspace's built-in Master Agent in the UI.                                                                                                          | No checkout: it cannot read `infra/` or `cadence/`, and it cannot change anything. Cheaper and faster per question, because there is no sandbox to start.                                                                           |
| `no-handoff`          | No other agents are deployed yet                                                                     | Delete §4 of the prompt and `references/roster.md`                                                                                                                                                   | E
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| `dms-too`             | Individuals want to ask privately                                                                    | Add each person's Slack **user id** (`U…`) to `channelIds` next to `allChannels`; DMs are listed by user, not by `D…` channel, and `allChannels` never covers them.                                   | The thread stops being multiplayer: nobody else sees the proposal or the go, so a DM go is one person approving spend alone. Keep §3 unchanged if you take this.                                                                    |
| `master-agent-slack`  | You only need questions answered, no repo and no pull requests                                       | Skip this cookbook. Put a Slack trigger on the workspace's built-in Master Agent in the UI.                                                                                                          | No checkout: it cannot read `infra/` or `cadence/`, and it cannot change anything. Cheaper and faster per question, because there is no sandbox to start.                                                                           |
| `no-handoff`          | No other agents are deployed yet                                                                     | Delete §4 of the prompt and `references/roster.md`                                                                                                                                                   | Every job is redone by this agent from scratch, without the owning agent's rules. Add §4 back the day the first pipeline deploys.                                                                                                    |
| `higher-sample-bar`   | Your runs are expensive per record, or touch people                                                  | Lower the 25-record threshold and the 5-record sample in §3 of the prompt                                                                                                                          
...[truncated 25 chars]

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
| `dms-too`             | Individuals want to ask privately                                                                    | Add each person's Slack **user id** (`U…`) to `channelIds` next to `allChannels`; DMs are listed by user, not by `D…` channel, and `allChannels` never covers them.                                   | The thread stops being multiplayer: nobody else sees the proposal or the go, so a DM go is one person approving spend alone. Keep §3 unchanged if you take this.                                                                    |
| `master-agent-slack`  | You only need questions answered, no repo and no pull requests                                       | Skip this cookbook. Put a Slack trigger on the workspace's built-in Master Agent in the UI.                                                                                                          | No checkout: it cannot read `infra/` or `cadence/`, and it cannot change anything. Cheaper and faster per question, because there is no sandbox to start.                                                                           |
| `no-handoff`          | No other agents are deployed yet                                                                     | Delete §4 of the prompt and `references/roster.md`                                                                                                                                                   | Every job is redone by this agent from scratch, without the owning agent's rules. Add §4 back the day the first pipeline deploys.                                                                                                    |
| `higher-sample-bar`   | Your runs are expensive per record, or touch people                                                  | Lower the 25-record threshold and the 5-record sample in §3 of the prompt                                                                                                                          
...[truncated 25 chars]

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The prompt instructs the agent to execute npx --yes @cargo-ai/cli if the CLI is not already installed, which pulls and runs the latest package version at execution time. That creates a supply-chain risk: a compromised package, malicious update, or dependency hijack could lead to arbitrary code execution in the agent environment with access to repo and workspace context.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · infra/agents/ask-cargo.prompt.ts (reported line 58)May include surrounding context.

ts
fails, this sandbox has no Cargo session: say so, and answer from the
   repository alone.

These workspace reads are free to run without asking:

- \`cargo-ai orchestration run count\` / \`run list\` / \`run get <uuid>\`
- \`cargo-ai orchestration batch list\` / \`batch get <uuid>\`

Static analysis

No suspicious patterns detected.