Back to skill

Security audit

adversarial-plan

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real planning tool, but its installer and examples can run unchecked code and its workflow can let AI tools change and merge repository files beyond a plan.

Review before installing. Prefer a local, pinned checkout instead of the curl-to-bash installer; avoid the documented sandbox-bypass examples; run only in a disposable or trusted repository; use --no-merge; inspect the full git diff before accepting output; and treat specs/findings as untrusted because they can influence provider actions and contract checks.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:22
Finding

Mutable Remote Installer Is Piped Directly into Bash

Content
View full analysis
Remediation
View remediation
adversarial-plan-v1.0.0.tar.gz' | sha256sum -c - ``` 6. Prefer installation from a reviewed local checkout. 7. Ensure installation writes only beneath an explicitly selected target directory and does not execute downloaded code as part of installation. ]]>

T08 · Insecure Dependencies

Error
Location
scripts/install.sh:11
Finding

Installer Clones and Imports Unpinned Remote Dependencies

Content
View full analysis
/dev/null 2>&1; then echo "detected: running from a checkout ($HERE) — skill already present" else if [ ! -d "$TARGET/$SKILL_DIR" ]; then git clone --depth 1 "$SKILL_URL" "$TARGET/$SKILL_DIR" else echo "skip: $TARGET/$SKILL_DIR already present" fi fi if [ ! -d "$TARGET/$COMMON_REPO" ]; then git clone --depth 1 "$COMMON_URL" "$TARGET/$COMMON_REPO" else echo "skip: $TARGET/$COMMON_REPO already present" fi ``` The installer then imports the retrieved modules: ```bash echo "Sanity check (import adversarial_common + adversarial_plan)..." SKILL_SCRIPTS_DIR="$TARGET/$SKILL_DIR/scripts" if [ -n "$HERE" ] && git -C "$HERE" rev-parse --git-dir >/dev/null 2>&1; then SKILL_SCRIPTS_DIR="$(git -C "$HERE" rev-parse --show-toplevel)/scripts" fi PYTHONPATH="$TARGET/$COMMON_REPO:$SKILL_SCRIPTS_DIR" python3 -c "import adversarial_common, adversarial_plan; print('OK: adversarial_common + adversarial_plan imported')" echo "Done." ``` ### Technical Analysis Both repositories are cloned using `--depth 1` without checking out a reviewed commit hash or signed release tag. Consequently, the dependency contents are determined by the repositories' default branch tips at installation time. The `adversarial-common` dependency is particularly security-sensi ...[truncated 1710 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/adversarial_plan.py:583
Finding

Specification-Controlled Acceptance Directives Reach a Command-Execution Gate

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/phases/phase_plan.py:128
Finding

LLM Providers Can Modify Arbitrary Repository Files That Are Subsequently Committed

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (50)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · README.md (reported line 62)May include surrounding context.

python3 scripts/adversarial_plan.py
--spec spec.md
--findings findings.json
--dev-cmd "pi --provider zai --model glm-5.2"
--review-cmd "pi --provider deepseek --model deepseek-v4-pro"

text

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The top-level purpose understates extensive orchestration features such as branch lifecycle management, CI/report behavior, provider selection/fallback, delegated execution, and rejection handling. In an agent setting, these hidden operational behaviors are security-relevant because they can alter repositories, influence pipelines, and expand the action surface far beyond 'generate a plan'.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The top-level purpose understates extensive orchestration features such as branch lifecycle management, CI/report behavior, provider selection/fallback, delegated execution, and rejection handling. In an agent setting, these hidden operational behaviors are security-relevant because they can alter repositories, influence pipelines, and expand the action surface far beyond 'generate a plan'.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The top-level purpose understates extensive orchestration features such as branch lifecycle management, CI/report behavior, provider selection/fallback, delegated execution, and rejection handling. In an agent setting, these hidden operational behaviors are security-relevant because they can alter repositories, influence pipelines, and expand the action surface far beyond 'generate a plan'.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The top-level purpose understates extensive orchestration features such as branch lifecycle management, CI/report behavior, provider selection/fallback, delegated execution, and rejection handling. In an agent setting, these hidden operational behaviors are security-relevant because they can alter repositories, influence pipelines, and expand the action surface far beyond 'generate a plan'.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The top-level purpose understates extensive orchestration features such as branch lifecycle management, CI/report behavior, provider selection/fallback, delegated execution, and rejection handling. In an agent setting, these hidden operational behaviors are security-relevant because they can alter repositories, influence pipelines, and expand the action surface far beyond 'generate a plan'.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The top-level purpose understates extensive orchestration features such as branch lifecycle management, CI/report behavior, provider selection/fallback, delegated execution, and rejection handling. In an agent setting, these hidden operational behaviors are security-relevant because they can alter repositories, influence pipelines, and expand the action surface far beyond 'generate a plan'.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The pipe into bash creates a dangerous chaining pattern where untrusted network content flows directly into a shell interpreter. This removes opportunities for inspection and amplifies the impact of any upstream compromise or content tampering.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
Requires the `adversarial-common` sibling repo (shared engine). One-line install:

curl -fsSL https://raw.githubusercontent.com/chpomob/adversarial-plan/main/scripts/install.sh | bash

or, from an existing checkout:

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
## CLI

<!-- CLI-FLAG-TABLE:START -->

| Flag | Value/default | Purpose |
|------|---------------|---------|

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
spec. See [Running plan steps without plan mode](references/run-plan-steps-without-plan-mode.md)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The example command explicitly tells the downstream tool to bypass approvals and sandbox protections, yet it is shown as a normal usage example without strong warnings. This trains users to disable core safety controls and materially increases the chance of destructive file, git, or shell actions in the target repository or environment.

Content

No source excerpt is available for this finding.

Ssd 1

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The command includes --dangerously-bypass-approvals-and-sandbox, which directly disables important safety boundaries for model-driven execution. In the context of a skill that already performs git, file, and shell orchestration, this can enable unchecked destructive or malicious actions with minimal friction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code creates dedicated branches and may squash-merge results back into the parent branch, but the skill description only presents it as producing a plan. Hidden repository mutation is dangerous because users may invoke what they believe is a read-mostly planning step and instead get persistent VCS state changes and merges.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Repository mutation and merge behavior go beyond the stated purpose of planning and can persist AI-generated artifacts into the codebase. If triggered in automation or by a trusting operator, this can alter branch history, contaminate reviews, or merge low-quality or policy-violating content under the guise of a planner.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Piping downloaded content directly into bash is a classic command-chaining anti-pattern that executes attacker-controlled content without inspection. In this skill context, the risk is heightened because the script proceeds to clone additional repositories and set Python import paths, extending the blast radius of any upstream compromise into persistent local code installation.

Content

Scanner excerpt · scripts/install.sh (reported line 4)May include surrounding context.

sh
#!/usr/bin/env bash
# Install adversarial-plan with its single dependency: adversarial-common (sibling layout).
# Usage:
#   Bootstrap (from anywhere):  curl -fsSL https://raw.githubusercontent.com/chpomob/adversarial-plan/main/scripts/install.sh | bash
#   From a checkout:            bash scripts/install.sh [TARGET_DIR]
# Target layout (siblings required):
#   <TARGET>/adversarial-plan            (this skill)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that FINALIZE will squash-merge approval unless --no-merge is set, which implies the tool may modify repository history/state by default. In an agent skill context, especially one designed to automate planning workflows, undocumented or weakly warned write actions increase the risk of unintended repository changes when a user assumes the tool is read-only or advisory.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents capabilities that include shell execution, filesystem access, and environment access, but it does not declare any explicit tool scope such as permissions or allowed-tools. That makes the effective privilege boundary unclear and increases the risk that an agent invokes the skill with broader powers than intended, especially given the documented git, install, and subprocess behaviors.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The triggering context is broad and does not clearly constrain when the skill should or should not be invoked, despite it having write, shell, git, and optional network behaviors. Overbroad invocation guidance makes accidental misuse more likely, including activation in repositories or situations where its orchestration powers are inappropriate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installation instructions execute a remote script directly via curl piped to bash, creating a classic remote code execution and supply-chain risk. This is especially unjustified for a planning skill because the documented purpose does not require blind execution of unreviewed network content during normal use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation presents a remote script piped to bash without a nearby warning, normalization of risk, or integrity verification guidance. Users may execute it casually, leading to arbitrary code execution if the script, hosting account, or transport path is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Deep-research mode adds externally sourced information gathering and provider command execution beyond the stated planner role. This increases the attack surface through network access, prompt injection from external content, and possibly untrusted subprocess behavior if users are not clearly warned and scoped.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest frames the skill as producing a plan, while the workflow documentation adds delegated execution paths and automatic merge/finalization behavior. This discrepancy can cause operators or automated controls to underestimate how much repository state the skill can change.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly recommends running Codex with --dangerously-bypass-approvals-and-sandbox, which disables important execution and approval safeguards. In a skill whose purpose is to automate an adversarial planning pipeline against a target repository, this materially increases the chance of destructive filesystem changes, unsafe command execution, or unintended actions on the host without adequate user confirmation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/run-plan-steps-without-plan-mode.md (reported line 23)May include surrounding context.

P3: Implement the model-agnostic quota resolver

  • Files: [adversarial_common/quota.py, adversarial_common/init.py, adversarial_common/tests/test_quota.py]
  • Dependencies: [P1, P2]
  • Description: Create QuotaResolver with TTL cache, state machine, thresholds...
  • Tests: Add tests for ordered fallback, cache, force modes, thresholds...
  • Risks: Cache sync, partial checker data...
text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The reference explicitly tells operators to run codex exec --dangerously-bypass-approvals-and-sandbox, which disables normal approval and sandbox protections while executing generated code against a repository. In the context of an adversarial planning/code-loop skill, this materially increases the chance that unsafe or malicious generated actions can modify files, exfiltrate data reachable from the workspace, or perform unintended operations without a human checkpoint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.