Back to skill

Security audit

codeagent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a code-agent orchestration guide, but its documented defaults can disable important permission and sandbox protections for delegated coding agents.

Review this carefully before installing. It is not clearly malicious, but use it only in repositories and accounts where delegated agents may safely run commands. Prefer setting CODEAGENT_SKIP_PERMISSIONS=false and CODEX_BYPASS_SANDBOX=false, use worktrees for changes, avoid unlimited parallel workers, and do not inject untrusted skills or prompts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:346
Finding

AI backends run with permission checks and sandbox protections disabled by default

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 346–347
Vulnerability Type: Default permission-prompt and sandbox bypass
Risk Level: High

Vulnerable snippet:

markdown
| `CODEAGENT_SKIP_PERMISSIONS` | Skip Claude backend permission prompts (`true`/`false`) | true |
| `CODEX_BYPASS_SANDBOX` | Control Codex sandbox bypass (`true`/`false`) | true |

Technical Analysis

The documented defaults set both CODEAGENT_SKIP_PERMISSIONS and CODEX_BYPASS_SANDBOX to true. Consequently, the Skill's standard invocation patterns can delegate tasks to AI coding backends without interactive permission approval and without the Codex sandbox boundary unless callers explicitly override these settings.

Backend actions may be influenced by task text, repository content, agent presets, and automatically injected skills. Disabling both safeguards allows such content to influence tool execution with the filesystem and process privileges of the account running codeagent-wrapper, rather than restricting operations to the intended project or isolated worktree.

The available project contains only the Skill documentation and does not include the wrapper implementation. The finding is therefore based on the effective operational defaults explicitly prescribed by SKILL.md; it does not establish that the wrapper itself contains malicious code.

Attack Path

  1. A user invokes codeagent-wrapper according to the documented standard patterns without overriding the two environment-variable defaults.
  2. The wrapper delegates a task to the Claude or Codex backend while processing task text, repository files, an agent preset, or an injected skill.
  3. Untrusted or unsafe instructions in that content induce the backend to request a sensitive tool action, such as executing a shell command or accessing a path outside the selected project.
  4. For Claude, the permission prompt is skipped by default; for Codex, the sandbox is bypassed by default.
  5. The r ...[truncated 811 chars]
Remediation
View remediation

Remediation Suggestions

  1. Change both defaults to false:
    • CODEAGENT_SKIP_PERMISSIONS=false
    • CODEX_BYPASS_SANDBOX=false
  2. Require explicit, per-task user authorization before enabling either bypass.
  3. Reject bypass activation through repository-controlled content, injected skills, or agent-generated parameters.
  4. Enforce a wrapper-level filesystem boundary around the selected work directory or isolated worktree rather than relying solely on backend controls.
  5. Apply least-privilege tool allowlists and deny access to unrelated credential stores, home-directory configuration, and system paths.
  6. Record bypass activation in structured audit logs, including the task, backend, requesting user, and authorized scope.
  7. For high-risk operations, retain an independent confirmation gate even when a backend-specific permission mechanism is disabled.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Defaulting CODEX_BYPASS_SANDBOX to true weakens or removes an important isolation boundary for model-driven code tasks. Because this skill is designed to run code-oriented agents and shell commands, bypassing sandbox protections by default materially increases the blast radius of prompt injection, bad tasking, or model mistakes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly exposes a --skip-permissions option for the Claude backend without pairing it with a prominent warning that interactive permission checks are a security control. In a code-execution/orchestration wrapper, suppressing approval prompts can let tasks perform filesystem or shell actions with reduced user awareness, increasing the chance of unintended or unsafe operations.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

EOF

text

Skills are loaded from `~/.claude/skills/{name}/SKILL.md`, stripped of YAML frontmatter, and injected into the task prompt.

## Usage Patterns

Static analysis

No suspicious patterns detected.