Back to skill

Security audit

cargo-orchestration

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Cargo orchestration helper that can perform real workspace actions, so it is suitable only for users who intend to run and manage Cargo workflows deliberately.

Install only if you intend to let Codex operate your Cargo workspace. Use a pinned @cargo-ai/cli version where possible, confirm `cargo-ai whoami`, use least-privilege/test credentials, sample 10-20 records before any batch, avoid empty filters unless you explicitly want every row, and treat signed download URLs and uploaded files as sensitive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest explicitly says 'downloading result files — use cargo-analytics', which narrows the skill's intended scope away from result retrieval. However, the file documents batch download, record download, and record download-outputs as supported workflows, indicating the skill does provide result-download behavior despite the stated exclusion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to match common requests like 'execute the action', 'ask the agent', or 'show me the workflow', which can cause this high-impact orchestration skill to activate too often. In context, that matters because the skill can run actions, create batches, message agents, and execute SQL, so over-triggering increases the chance of unintended operational or costly actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill instructs users to run npx @cargo-ai/cli, which resolves the latest package at execution time rather than a pinned, reviewed version. That creates a supply-chain risk: a compromised or newly broken release could be fetched and executed immediately in a privileged local environment.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest-level guidance states that downloading result files should use another skill, creating an explicit intent boundary. Later, the document contradicts that boundary by instructing users to use cargo-ai orchestration batch download to retrieve results, which is a direct contradiction in the skill's own documentation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill's manifest says downloading result files belongs to cargo-analytics, but this section explicitly presents record download and record download-outputs as capabilities of this skill. That is an active contradiction between the stated intent and the documented behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example grants an AI agent permission to enrich leads and update Salesforce without any warning that these actions can modify external systems or process customer data. In a skill specifically designed to execute tools and orchestrate workflows, omission of side-effect warnings increases the chance of unintended writes, unauthorized data propagation, or privacy-impacting operations being run by users who assume the example is read-only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This combined example normalizes a workflow where the agent researches a company, enriches data, and updates a CRM, but provides no notice that the operation has external side effects. Because the skill's purpose is orchestration and execution, users may run the example against production systems, leading to accidental record changes, data quality issues, or unintended dissemination of sensitive business data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The end-to-end flow includes uploading a knowledge file and using email-finding/research actions without warning about privacy, consent, or downstream handling of personal data. In this context, the skill enables collection, enrichment, and possible storage or transmission of sensitive information, so missing guidance materially raises the risk of privacy violations, over-collection, and use of unauthorized data sources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example explicitly demonstrates creating a batch with an empty filter, which enrolls every row in the model, but it does not give a strong, proximate warning about operational impact such as mass outbound actions, bulk data changes, cost spikes, or triggering external integrations at scale. In this orchestration skill, users are likely to copy-paste commands directly, so a broad-scope example materially increases the risk of accidental large-scale execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The --enrich --sync example can actively trigger connected enrichment tooling and persist changes back to the model, but the example presents it as a routine fetch without a prominent side-effect warning. In this skill context, users may reasonably assume a read operation is safe, so this omission can lead to unintended writes, cascading automations, data corruption, or unexpected spend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation gives concrete commands to update and deploy draft releases and to execute workflows against live tooling without an explicit warning that these actions can change production behavior or trigger real downstream effects. In an orchestration skill, users may copy-paste examples directly, so omission of scope/impact warnings increases the chance of accidental mass execution or unintended deployment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The batch example explicitly states that an empty filter means all rows, but it does not pair that with a strong warning that the command can execute across an entire model or segment. In this skill context, batch operations are designed for large-scale orchestration, so users could unintentionally launch organization-wide actions, causing broad data changes, messages, API calls, or cost spikes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file includes commands to upload a CSV to workspace storage and later download batch results, but it does not warn users that record data will be sent to remote storage/services and may contain sensitive information. For a documentation file, SQP-2 applies when behaviors affecting user data or privacy are described without disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly supports a raw SQL filter via a sql kind with an arbitrary clause, which expands the skill from orchestration into direct query expression. If downstream components interpolate or execute this clause without strict sandboxing or parameterization, users can bypass higher-level filter controls and potentially access or manipulate data in unintended ways. In this skill context, exposing SQL is more dangerous because the skill already supports runtime-table querying and broad execution across segments, increasing the blast radius of misuse.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/nodes.md (reported line 179)May include surrounding context.

}

text

| Field        | Values                                   | Description                                                                                 |
| ------------ | ---------------------------------------- | ------------------------------------------------------------------------------------------- |
| `kind`       | `"templateExpression"`, `"jsExpression"` | Template expressions use `{{...}}` syntax; JS expressions are raw JS                        |
| `expression` | string                                   | The expression to evaluate                                                                  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/nodes.md (reported line 254)May include surrounding context.

md
the model's `/records/ingest` webhook: that URL is for systems outside Cargo, and
calling it from a node costs an HTTP node, a payload script, and a token in a header.

| actionSlug    | Purpose                                         | childrenCount | Config                                                                                     |
| ------------- | ----------------------------------------------- | -------- | ------------------------------------------------------------------------------------------ |
| `modelUpsert` | Update the matching record, or insert one       | 1        | `{"modelUuid", "matchingColumnSlug", "matchingValue", "mappings": [{"columnSlug", "value"}]}` |
| `modelUpdate` | Update matching records only                    | 1        | Same as `modelUpsert`                                                                      |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/nodes.md (reported line 293)May include surrounding context.

md
### AI and code

| actionSlug | Purpose             | childrenCount | Config                                                                                                 |
| ---------- | ------------------- | -------- | ------------------------------------------------------------------------------------------------------ |
| `agent`    | Inline AI agent     | 1        | `{"prompt": "...", "advancedSettings": {"connectorUuid": "...", "languageModelSlug": "gpt-4.1-mini"}}` |
| `python`   | Run Python code     | 1        | `{"script": "..."}`                                                                                    |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/nodes.md (reported line 296)May include surrounding context.

md
| actionSlug | Purpose             | childrenCount | Config                                                                                                 |
| ---------- | ------------------- | -------- | ------------------------------------------------------------------------------------------------------ |
| `agent`    | Inline AI agent     | 1        | `{"prompt": "...", "advancedSettings": {"connectorUuid": "...", "languageModelSlug": "gpt-4.1-mini"}}` |
| `python`   | Run Python code     | 1        | `{"script": "..."}`                                                                                    |
| `script`   | Run JavaScript code | 1        | `{"script": "..."}`                                                                                    |

The `agent` action requires `advancedSettings.connectorUuid` (an AI provider connector — get it from `connector list`). Optional fields: `actions`, `resources`, `capabilities`, `output` (structured output with `{"type": "jsonSchema", "jsonSchema": {...}}`), `advancedSettings.temperature`, `advancedSettings.maxSteps`, `advancedSettings.systemPrompt`.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/nodes.md (reported line 297)May include surrounding context.

md
| actionSlug | Purpose             | childrenCount | Config                                                                                                 |
| ---------- | ------------------- | -------- | ------------------------------------------------------------------------------------------------------ |
| `agent`    | Inline AI agent     | 1        | `{"prompt": "...", "advancedSettings": {"connectorUuid": "...", "languageModelSlug": "gpt-4.1-mini"}}` |
| `python`   | Run Python code     | 1        | `{"script": "..."}`                                                                                    |
| `script`   | Run JavaScript code | 1        | `{"script": "..."}`                                                                                    |

The `agent` action requires `advancedSettings.connectorUuid` (an AI provider connector — get it from `connector list`). Optional fields: `actions`, `resources`, `capabilities`, `output` (structured output with `{"type": "jsonSchema", "jsonSchema": {...}}`), `advancedSettings.temperature`, `advancedSettings.maxSteps`, `advancedSettings.systemPrompt`.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file documents cargo-ai orchestration record download returning a signed URL for downloading records, which can expose user or workspace data if shared or handled carelessly. The surrounding description provides no warning about the sensitivity of the downloaded file or the signed URL despite this being a data-export capability.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The documentation recommends invoking the CLI via npx @cargo-ai/cli without a pinned version, which can fetch whatever package version is current at execution time. In an orchestration skill that encourages users to run operational commands, this creates a supply-chain risk: behavior can change unexpectedly, and a compromised or malicious newly-published version could be executed immediately.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 17)May include surrounding context.

md
## Runs and batches

| Symptom                             | Cause                                              | Fix                                                                                                         |
| ----------------------------------- | -------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| Run stuck in `pending`              | Workflow may be paused or have no deployed release | Check that the play/tool `isEnabled` is `true`; verify a release exists with `release list --workflow-uuid` |
| Batch never finishes                | Individual runs may be erroring or stuck           | List runs for the batch: `run list --workflow-uuid <uuid> --batch-uuid <uuid>` and check for errors         |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 39)May include surrounding context.

md
## Orchestration queries (`orchestration query execute`)

| Symptom                                                  | Cause                                            | Fix                                                                                                            |
| -------------------------------------------------------- | ------------------------------------------------ | -------------------------------------------------------------------------------------------------------------- |
| `errorMessage` with "Table … doesn't exist"              | Used a schema-prefixed name                      | Reference tables as `runs`, `batches`, `spans`, `records` — no schema prefix                                   |
| `errorMessage: "Code: 158. Memory limit exceeded"`       | Scanned too many rows                            | Narrow the time window (`created_at > now() - INTERVAL N DAY`) or aggregate before returning                   |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 62)May include surrounding context.

md
The response has three top-level fields:

| Field                | What it gives you                                                                                |
| -------------------- | ------------------------------------------------------------------------------------------------ |
| `run.executions[]`   | Node-by-node trace (which node ran, status, routing)                                             |
| `runContext`         | Full per-node output, keyed by `nodeSlug` — the actual data referenced as `{{nodes.<slug>...}}`  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 70)May include surrounding context.

md
The response has three top-level fields:

| Field                | What it gives you                                                                                |
| -------------------- | ------------------------------------------------------------------------------------------------ |
| `run.executions[]`   | Node-by-node trace (which node ran, status, routing)                                             |
| `runContext`         | Full per-node output, keyed by `nodeSlug` — the actual data referenced as `{{nodes.<slug>...}}`  |

Static analysis

No suspicious patterns detected.