Back to skill

Security audit

Orchestrix Guide

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed automation guide, but it asks users to disable Claude Code permission checks and auto-approve trust and approval prompts during code-changing workflows.

Review before installing. This skill is not showing exfiltration or destructive intent, but you should only use it in an isolated project or container, avoid the --dangerously-skip-permissions alias, keep normal Claude Code approvals enabled, and do not auto-accept folder trust for repositories you have not inspected.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:887
Finding

Claude Code Permission Enforcement Is Explicitly Disabled

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 887-891
Vulnerability Type: Permission bypass and excessive agent privileges
Risk Level: High

Vulnerable Code

bash
alias cc='claude --dangerously-skip-permissions'

Technical Analysis

The Skill requires the cc command to invoke Claude Code with the --dangerously-skip-permissions option. The documented workflows subsequently launch cc inside project directories and authorize development agents to generate files, modify source code, execute tests, and create Git commits.

This option deliberately disables Claude Code's normal interactive permission controls. It removes a security boundary intended to let users review sensitive operations such as executing shell commands or accessing files outside the immediate task scope.

Although the Skill's legitimate function requires project automation, globally disabling permission enforcement is broader than necessary. The resulting execution environment implicitly trusts instructions received from project files, agent output, and the externally integrated Orchestrix workflow.

Attack Path

  1. A user runs the documented workflow in a repository containing malicious or compromised instructions.
  2. The workflow starts cc, which resolves to claude --dangerously-skip-permissions.
  3. Claude Code or an activated agent processes attacker-controlled repository content.
  4. That content induces a sensitive tool action, such as running an arbitrary command or reading or changing files beyond those required by the development task.
  5. Because permission enforcement is disabled, the action can execute without an informed user confirmation.
  6. The action runs with the operating-system privileges of the user who launched Claude Code.

Impact Assessment

Successful exploitation can provide access equivalent to the local account running the Skill. Depending on that account's permissions and Claude ...[truncated 689 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the unsafe alias and invoke Claude Code with normal permission enforcement:
    bash
    alias cc='claude'
    
  2. Define a narrow allowlist for the specific tools, commands, and project paths required by each workflow stage.
  3. Require explicit user confirmation for shell execution, access outside the selected project, credential access, destructive file operations, network operations, and Git publication actions.
  4. Run development agents in an isolated container or restricted operating-system account with only the current repository mounted.
  5. Prevent agents from accessing SSH keys, cloud credentials, browser profiles, environment-secret stores, and unrelated home-directory content.
  6. Separate document-generation privileges from code-execution privileges so planning agents cannot execute development commands unnecessarily.
  7. Record approved operations in an audit log and fail closed when an operation does not match the configured policy.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:145
Finding

Generic Permission Prompts and Project Trust Dialogs Are Automatically Accepted

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 145-160 and 206-208
Vulnerability Type: Unvalidated automatic authorization
Risk Level: High

Vulnerable Code

The workflow detects a generic terminal indicator and automatically submits an affirmative response:

bash
tmux capture-pane -t {session}:{window} -p -S -10 | grep -q '◐'
bash
tmux send-keys -t {session}:{window} "y"
sleep 1
tmux send-keys -t {session}:{window} Enter
sleep 2

The Skill also states that start-orchestrix.sh and ensure-session.sh scan terminal output for the strings below and automatically submit Enter to accept the dialog:

text
trust this folder
safety check

Technical Analysis

The approval mechanism identifies a permission request only through the generic ◐ terminal symbol. It does not parse the requested operation, verify the target path, determine the requested privilege, or distinguish a routine operation from a destructive or sensitive action.

The project trust mechanism similarly accepts folder trust and safety dialogs automatically. Trust prompts are a security boundary: accepting one may allow repository-provided configuration, hooks, instructions, or tooling to influence subsequent agent behavior. Automatically accepting that boundary without verifying repository origin or contents defeats its protective purpose.

This weakness is especially significant because the same Skill separately recommends launching Claude Code with permission checks disabled. Even without that separate configuration, however, unconditional approval remains independently unsafe because the automation cannot determine what it is authorizing.

The helper scripts referenced by the documentation are not included in the audited project. Their implementation therefore could not be independently verified; this finding is based on the explicit behavior required by SKILL.md.

Attack Path

  1. A user o ...[truncated 1674 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic affirmative responses to generic terminal indicators.
  2. Parse and display the complete permission request, including the command, arguments, target paths, network destination, and requested capability.
  3. Require explicit user confirmation for each sensitive operation rather than treating all prompts as equivalent.
  4. Never automatically accept folder-trust or safety-check dialogs. Require the user to review the repository origin and contents first.
  5. Establish a deny-by-default authorization policy. Automatically permit only exact, predefined low-risk operations within the selected project directory.
  6. Reject requests involving paths outside the project, credentials, shell initialization files, SSH material, system configuration, network uploads, destructive commands, or privilege changes.
  7. Match structured prompt state or an authenticated API response instead of scraping a generic terminal glyph.
  8. Bind approvals to a specific expected request and expire them immediately after use to prevent stale or mismatched authorization.
  9. Run untrusted repositories in an isolated container or sandbox before granting any project trust.
  10. Include and audit the referenced helper scripts so their trust and approval behavior can be reviewed directly.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs operators to alias cc to claude --dangerously-skip-permissions, explicitly disabling permission safeguards for an AI agent that is then given automated tmux-based control over project workflows. In this context, the guide also auto-accepts trust prompts and approval prompts, so the combination materially increases the chance of unauthorized file changes, command execution, or other high-impact actions without meaningful human review.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document recommends a permissions-bypassing execution mode without any prominent user-facing warning about the security implications. Because the rest of the skill automates command delivery, trust acceptance, and approval handling, omitting a warning makes unsafe deployment more likely and reduces operator awareness of the elevated risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The statement describes this document as the sole operating manual and requires strict adherence, while the manual content is presented in Chinese. This creates a de facto language constraint without opt-in, alternative locale support, or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description explicitly says the skill defines two operational phases: Planning and Development. However, the body of the skill later introduces a separate 'Phase C: 测试阶段' with its own procedures, completion criteria, and remediation loop, which exceeds the described phase structure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.