Back to skill

Security audit

Adversarial Code Review

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real code-review tool, but it uses unsafe remote installation and can send broad project contents or quota credentials to external tools/providers.

Install only after reviewing and pinning the installer/dependencies yourself. Use narrow diff or file modes when possible, avoid whole-directory review on repos containing .env files, keys, token caches, or private configs, and do not run the quota checker or external-provider examples unless you understand which credentials and code will be sent to which services.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:25
Finding

Mutable Remote Installer Is Executed Directly Through Bash

Content
View full analysis
/dev/null 2>&1; then SKILL_SCRIPTS_DIR="$(git -C "$HERE" rev-parse --show-toplevel)/scripts" fi PYTHONPATH="$TARGET/$COMMON_REPO:$SKILL_SCRIPTS_DIR" python3 -c "import adversarial_common, adversarial_review; print('OK: adversarial_common + adversarial_review imported')" ``` ### Technical Analysis The documented installation command downloads the current contents of a mutable `main` branch and immediately feeds them to Bash. There is no opportunity for the user to inspect the downloaded script and n ...[truncated 1955 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/adversarial_review.py:292
Finding

Whole-Project Review Can Send Secret-Bearing Files to External Model Providers

Content
View full analysis
= limit: return sorted(out) return sorted(out) ``` `scripts/adversarial_review.py:336-358`: ```python files = changed_files_from_diff(diff_text) or _list_tree(project_dir) parts.append("=== Files under review ===\n" + "\n".join(files) + "\n") bodies = [] for rel in files: rel_path = Path(rel) if rel_path.is_absolute(): continue try: # ponytail: accepted TOCTOU — resolve/is_file then a separate read # is a narrow race, low-severity for this single-user local CLI. candidate = (project_root / rel_path).resolve() if candidate == project_root or project_root not in candidate.parents: print(f"! WARNING: ...[truncated 4024 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/check-ai-quota.py:563
Finding

Quota Checker Defaults to Broad Credential-Using Checks Through an External Plugin

Content
View full analysis
ModuleType: """Load the optional external adapter only when a check is requested.""" global _QUOTA_API if _QUOTA_API is not None: return _QUOTA_API with _QUOTA_API_LOCK: if _QUOTA_API is not None: return _QUOTA_API plugin_path = str(PLUGIN_DIR) if plugin_path not in sys.path: sys.path.insert(0, plugin_path) try: _QUOTA_API = importlib.import_module("quota_api") except Exception as exc: raise RuntimeError(_QUOTA_API_ERROR) from exc return _QUOTA_API ``` `scripts/check-ai-quota.py:122-140`: ```python def fetch_claude_quota() -> dict[str, Any] | None: return _adapter_fetcher("fetch_claude_quota")() def fetch_codex_quota() -> dict[str, Any] | None: return _adapter_fetcher("fetch_codex_quota")() def fetch_gemini_quota() -> dict[str, Any] | None: return _adapter_fetcher("fetch_gemini_quota")() def fetch_glm_quota() -> dict[str, Any] | None: return _adapter_fetcher("fetch_glm_quota")() def fetch_deepseek_balance() -> dict[str, Any] | None: return _adapter_fetcher("fetch_deepseek_balance")() ``` `scripts/check-ai-quota.py:563-566`: ```python provider_names = tuple(provider ...[truncated 2898 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (64)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about an adversarial code review skill with multiple reviewer roles, git-isolated worktrees, cross-validation, and synthesis arbitration. The supplied code does none of that. Its clear primary purpose is an AI provider quota checker CLI. It dynamically imports a quota adapter plugin, reads credentials from filesystem locations and environment variables, queries multiple external AI service endpoints, and reports usage/balance in text or JSON. There is no evidence of git worktrees, review agents/roles, code analysis, cross-validation logic, or synthesis precedence. This is a strong description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents the skill as a code-review system with specific review roles and synthesis logic. However, the supplied code chunk is purely a bootstrap/install script. Its primary purpose is to install the skill and a dependency into a sibling directory layout and verify imports. That is materially different from the described operational behavior. While install scripts can be a supporting detail of a skill, this chunk does not actually reflect the declared functionality and instead performs undeclared installation, network, and filesystem actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a skill whose main function is to conduct a multi-agent adversarial code review workflow with distinct reviewer roles and a synthesis step that arbitrates outcomes. The supplied code does not implement that review behavior. Instead, it is a test module focused on validating lower-level git/worktree/diff utilities, source construction, path-containment and symlink safety checks, CLI parsing, and error/reporting behavior. While git-isolated worktrees are tangentially relevant to the description, the core claimed capabilities—dual reviewers, cross-validation, and synthesis verdict precedence—are absent from this chunk. Therefore the code chunk's actual purpose is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about an adversarial code review system with multiple reviewer personas and synthesis logic. The supplied code chunk does not perform code review at all; it only defines tests for a quota-checking CLI and plugin adapter behavior. Its primary purpose, resources, and outputs are entirely different from the declared purpose. This is a clear material mismatch, not merely an implementation detail.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The curl ... | bash chain is a classic command-chaining anti-pattern because it removes the inspection boundary between download and execution. Any malicious or unexpected response body is immediately interpreted by the shell, turning content delivery issues into instant code execution.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
Requires the `adversarial-common` sibling repo (shared engine). One-line install:

curl -fsSL https://raw.githubusercontent.com/chpomob/adversarial-code-review/main/scripts/install.sh | bash

or, from an existing checkout:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

md
any Hermes skill, run the full checklist in `references/pre-publication-cleanup.md`:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/ai-quota-apis.md (reported line 28)May include surrounding context.

md
## Claude Code (Pro subscription)

- **Token**: `~/.claude/.credentials.json` → `claudeAiOauth.accessToken`
- **Endpoint**: `https://api.anthropic.com/api/oauth/usage`
- **Status**: First-party Anthropic endpoint, but undocumented and
  community-discovered; it is not a supported public API contract and may change.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/pre-publication-review-checklist.md (reported line 41)May include surrounding context.

md
## Claude Code (Pro subscription)

- **Token**: `~/.claude/.credentials.json` → `claudeAiOauth.accessToken`
- **Endpoint**: `https://api.anthropic.com/api/oauth/usage`
- **Status**: First-party Anthropic endpoint, but undocumented and
  community-discovered; it is not a supported public API contract and may change.

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · references/codex-claude-hardware-review.md (reported line 28)May include surrounding context.

Prefer inline prompt over pipe to avoid PTY buffer/deadlock issues:

bash
codex exec \
  -C /path/to/project \
  --skip-git-repo-check --dangerously-bypass-approvals-and-sandbox \
  -c model='gpt-5.6-sol' -c model_reasoning_effort='medium' \

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · references/codex-claude-hardware-review.md (reported line 43)May include surrounding context.

to a file and use "$(< /tmp/prompt.txt)":

bash
codex exec ... "$(< /tmp/prompt.txt)" 'short fallback instruction'

The prompt should include: task description, hardware context, JSON output format,

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
95% confidence
Finding

This guidance instructs the operator to send review/planning inputs to an external model and to run Codex with --sandbox danger-full-access, which materially increases exposure of repository contents and local environment data to an external agent. In a security-review skill, this is especially dangerous because findings, code snippets, and project context often contain sensitive source, secrets, or vulnerability details, and the bypass of normal repo/sandbox protections reduces defense-in-depth.

Content

Scanner excerpt · references/post-review-fix-planning.md (reported line 32)May include surrounding context.

bash
# Model A: Codex
cd /path/to/project
codex exec --skip-git-repo-check --sandbox danger-full-access < plan-spec-a.txt

# Model B: GLM-5.2 (pi) or Claude tmux
pi -p --provider zai --model glm-5.2 < plan-spec-b.txt

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill explicitly recommends using an external provider (zai / GLM-5.2) for fix-plan generation, which can disclose proprietary code-review findings, file paths, and vulnerability information to a third party. Although selecting an external model is not inherently malicious, in this context the skill normalizes outbound transfer of potentially sensitive security-analysis data without any mention of approval, redaction, retention, or provider trust constraints.

Content

Scanner excerpt · references/post-review-fix-planning.md (reported line 35)May include surrounding context.

codex exec --skip-git-repo-check --sandbox danger-full-access < plan-spec-a.txt

Model B: GLM-5.2 (pi) or Claude tmux

pi -p --provider zai --model glm-5.2 < plan-spec-b.txt

text

Each model writes its plan to a file (e.g. PLAN_CODEX.md, PLAN_GLM.md).

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script is designed to locate local OAuth/API credentials and contact multiple third-party services, transmitting account-linked secrets and metadata unrelated to code review. Within an agent skill, this materially expands data-exfiltration risk because running the skill can probe personal accounts and disclose IP, timing, provider usage, and account state to external services.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The file explicitly describes reading OAuth credentials from ~/.claude/.credentials.json, which is credential access to sensitive local tokens. In an agent skill, access to home-directory secrets is particularly dangerous because the skill can leverage the user's existing authenticated state to query external services without introducing new credentials, enabling stealthy account reconnaissance or abuse.

Content

Scanner excerpt · scripts/check-ai-quota.py (reported line 13)May include surrounding context.

python
``references/ai-quota-apis.md``):

* Claude: ``https://api.anthropic.com/api/oauth/usage``; OAuth token from
  ``~/.claude/.credentials.json``; first-party but undocumented and
  community-discovered; sends the OAuth token and exposes account usage.
* Codex: ``https://chatgpt.com/backend-api/wham/usage``; OAuth token from
  ``~/.codex/auth.json``; first-party/official service but not a documented

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash construct turns a documentation example into immediate shell execution of remote content with no opportunity for review or integrity validation. In an installer context this is especially dangerous because users are primed to run the command as-is, making any upstream compromise or typo-squatting event an instant remote code execution vector.

Content

Scanner excerpt · scripts/install.sh (reported line 4)May include surrounding context.

sh
#!/usr/bin/env bash
# Install adversarial-code-review with its single dependency: adversarial-common (sibling layout).
# Usage:
#   Bootstrap (from anywhere):  curl -fsSL https://raw.githubusercontent.com/chpomob/adversarial-code-review/main/scripts/install.sh | bash
#   From a checkout:            bash scripts/install.sh [TARGET_DIR]
# Target layout (siblings required):
#   <TARGET>/adversarial-code-review            (this skill)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_diff_git.py (reported line 145)May include surrounding context.

python
project = tmp_path / "workspace" / "project"
    project.mkdir(parents=True)
    sentinel = "PARENT_PATH_SENTINEL"
    (tmp_path / "secret.txt").write_text(sentinel)
    diff = (
        "diff --git a/../../secret.txt b/../../secret.txt\n"
        "+++ b/../../secret.txt\n"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_diff_git.py (reported line 147)May include surrounding context.

python
project = tmp_path / "workspace" / "project"
    project.mkdir(parents=True)
    sentinel = "PARENT_PATH_SENTINEL"
    (tmp_path / "secret.txt").write_text(sentinel)
    diff = (
        "diff --git a/../../secret.txt b/../../secret.txt\n"
        "+++ b/../../secret.txt\n"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_diff_git.py (reported line 148)May include surrounding context.

python
project = tmp_path / "workspace" / "project"
    project.mkdir(parents=True)
    sentinel = "PARENT_PATH_SENTINEL"
    (tmp_path / "secret.txt").write_text(sentinel)
    diff = (
        "diff --git a/../../secret.txt b/../../secret.txt\n"
        "+++ b/../../secret.txt\n"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_diff_git.py (reported line 162)May include surrounding context.

python
project = tmp_path / "workspace" / "project"
    project.mkdir(parents=True)
    sentinel = "PARENT_PATH_SENTINEL"
    (tmp_path / "secret.txt").write_text(sentinel)
    diff = (
        "diff --git a/../../secret.txt b/../../secret.txt\n"
        "+++ b/../../secret.txt\n"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_diff_git.py (reported line 201)May include surrounding context.

python
project = tmp_path / "workspace" / "project"
    project.mkdir(parents=True)
    sentinel = "PARENT_PATH_SENTINEL"
    (tmp_path / "secret.txt").write_text(sentinel)
    diff = (
        "diff --git a/../../secret.txt b/../../secret.txt\n"
        "+++ b/../../secret.txt\n"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_diff_git.py (reported line 204)May include surrounding context.

python
project = tmp_path / "workspace" / "project"
    project.mkdir(parents=True)
    sentinel = "PARENT_PATH_SENTINEL"
    (tmp_path / "secret.txt").write_text(sentinel)
    diff = (
        "diff --git a/../../secret.txt b/../../secret.txt\n"
        "+++ b/../../secret.txt\n"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_diff_git.py (reported line 215)May include surrounding context.

python
project = tmp_path / "workspace" / "project"
    project.mkdir(parents=True)
    sentinel = "PARENT_PATH_SENTINEL"
    (tmp_path / "secret.txt").write_text(sentinel)
    diff = (
        "diff --git a/../../secret.txt b/../../secret.txt\n"
        "+++ b/../../secret.txt\n"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_diff_git.py (reported line 228)May include surrounding context.

python
project = tmp_path / "workspace" / "project"
    project.mkdir(parents=True)
    sentinel = "PARENT_PATH_SENTINEL"
    (tmp_path / "secret.txt").write_text(sentinel)
    diff = (
        "diff --git a/../../secret.txt b/../../secret.txt\n"
        "+++ b/../../secret.txt\n"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_diff_git.py (reported line 243)May include surrounding context.

python
project = tmp_path / "workspace" / "project"
    project.mkdir(parents=True)
    sentinel = "PARENT_PATH_SENTINEL"
    (tmp_path / "secret.txt").write_text(sentinel)
    diff = (
        "diff --git a/../../secret.txt b/../../secret.txt\n"
        "+++ b/../../secret.txt\n"

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · tests/test_quota_cli.py (reported line 293)May include surrounding context.

python
script = Path(__file__).parents[1] / "scripts" / "check-ai-quota.py"
    isolated_home = tmp_path / "home"
    isolated_home.mkdir()
    env = os.environ.copy()
    env.update(
        {
            "HOME": str(isolated_home),

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_quota_cli.py:23