Back to skill

Security audit

Coding PM

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed coding automation workflow, but it asks users to disable important permission boundaries and runs background coding agents with very broad authority.

Install only if you are comfortable giving a background Claude Code process broad access to your project and potentially more of your home directory after workspace-only mode is disabled. Prefer running it in a dedicated container, VM, or low-privilege account with no unrelated secrets, and avoid using it on production repositories until task-name validation, prompt quoting, scoped filesystem access, and safer cancel cleanup are added.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:75
Finding

Shell Command Injection Through Unsanitized Task, Path, and Request Values

Content
View full analysis
rev-parse --abbrev-ref HEAD) # Create worktree TASK= # 2-3 words, kebab-case, from request git -C worktree add ~/.worktrees/$TASK -b feat/$TASK # Create supervisor directory for wake markers mkdir -p ~/.worktrees/$TASK/.supervisor ``` The same workflow embeds request-controlled text directly into a shell command: ```bash bash pty:true workdir:~/.worktrees/$TASK background:true command: claude -p "Context: Request: Instructions: - Research the codebase and relevant best practices - Design the architecture following the Engineering Practices in your system prompt - Produce a detailed implementation plan with test strategy - Wrap plan in [PLAN_START] and [PLAN_END] - Do NOT execute yet" \ --output-format json \ --dangerously-skip-permissions \ --allowedTools "Read,Glob,Grep,LS,WebSearch,WebFetch,Bash(git log *,git diff *,git show *,git status,git branch --list *)" \ --append-system-prompt-file "$SUPERVISOR_PROMPT" ``` ### Technical Analysis The workflow derives `TASK` from the user's request and uses it in shell paths and Git branch names without specifying mandatory validation, escaping, or safe argument-array construction. The project directory and original request are also represented as direct substitutions into shell commands. In particular, the original request is inserted inside a double-quoted `claude -p` argument. Shell metacharacters that remain meaningful inside double quotes, such as command substitutions using `$(...)` or backticks, may be evaluated by the shell. An embedded quote can also terminate the intended argument and introduce additional shell syntax. Unquot ...[truncated 1814 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:92
Finding

Permission Checks Are Disabled During Nominally Read-Only Planning

Content
View full analysis
Request: Instructions: - Research the codebase and relevant best practices - Design the architecture following the Engineering Practices in your system prompt - Produce a detailed implementation plan with test strategy - Wrap plan in [PLAN_START] and [PLAN_END] - Do NOT execute yet" \ --output-format json \ --dangerously-skip-permissions \ --allowedTools "Read,Glob,Grep,LS,WebSearch,WebFetch,Bash(git log *,git diff *,git show *,git status,git branch --list *)" \ --append-system-prompt-file "$SUPERVISOR_PROMPT" ``` The project explicitly acknowledges the control weakness at `SKILL.md`, lines 375-377: ```text 2. **`--dangerously-skip-permissions`** — Claude Code requires this flag for non-interactive (background) execution where no TTY is available for permission prompts. This is the standard approach for any Claude Code automation (CI/CD, scripts, background agents). All `claude` invocations also use `--output-format json` for structured, parseable output. **Note:** `--dangerously-skip-permissions` may override `--allowedTools` restrictions — the planning phase tool restriction is a best-effort guardrail, not a hard sandbox. The Supervisor Protocol and PM monitoring provide additional enforcement. ``` ### Technical Analysis The planning phase is presented as read-only and supplies an `--allowedTools` list intended to limit the coding agent to repository inspection and selected Git commands. However, the same invocation uses `--dangerously-skip-permissions`. The documentation expressly states that this flag may override the allowlist. Therefore, the purported read-o ...[truncated 2038 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
README.md:50
Finding

Global Workspace Filesystem Isolation Is Disabled

Content
View full analysis
/`, which is outside the OpenClaw workspace directory. The agent needs filesystem access to these worktree paths. ``` The same requirement is documented at `SKILL.md`, line 375: ```text 1. **`tools.fs.workspaceOnly = false`** — Git worktrees are created at `~/.worktrees//`, outside the OpenClaw workspace. Without this setting, the agent cannot read/write worktree files. This is a session-level OpenClaw config change; re-enable it when not using coding-pm on sensitive systems. ``` ### Technical Analysis The installation procedure disables the platform's workspace-only filesystem restriction so that worktrees can be created under `~/.worktrees`. This changes a broad platform-level security setting rather than granting access only to a single task directory. Git worktree isolation does not constitute filesystem isolation. A worktree separates repository state and branches, but it does not prevent a process from reading or modifying other paths available to the same operating-system user. The instructions merely recommend re-enabling the setting when the Skill is not in use. They do not automatically restore it after completion, cancellation, failure, or process termination. Consequently, the expanded access can remain active across tasks and sessions. The risk is compounded by launching the delegated agent with permission checks disabled during both planning and execution. ### Attack Path 1. The operator follows the documented setu ...[truncated 1349 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (17)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 73)May include surrounding context.

md
**Additional guardrails:**
- Supervisor Protocol (`references/supervisor-prompt.md`) requires the coding-agent to ask before deleting files or modifying credentials
- PM scans coding-agent output for dangerous patterns (`rm -rf`, `DROP TABLE`, `chmod 777`, `--force`, `--no-verify`, credential file modifications)
- Human-in-the-loop: plan approval gate before execution begins, decision escalation during execution
- Skill is user-invocable only — only runs when you explicitly send `/dev <request>`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 382)May include surrounding context.

md
**Additional guardrails:**
- Supervisor Protocol (`references/supervisor-prompt.md`) requires the coding-agent to ask before deleting files or modifying credentials
- PM scans coding-agent output for dangerous patterns (`rm -rf`, `DROP TABLE`, `chmod 777`, `--force`, `--no-verify`, credential file modifications)
- Human-in-the-loop: plan approval gate before execution begins, decision escalation during execution
- Skill is user-invocable only — only runs when you explicitly send `/dev <request>`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
1. **Requirements coverage**: Does the plan address ALL points in the user's request?
2. **Test plan**: Does it include testing/verification steps?
3. **Risk scan**: Any dangerous operations? (rm -rf, DROP TABLE, chmod 777, force push, --no-verify, credential files, production config changes)
4. **Format**: Is it clear, readable, and actionable?

### Issues found -> feedback to coding-agent (don't bother user)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 381)May include surrounding context.

md
- **Supervisor Protocol** (`references/supervisor-prompt.md`): The coding-agent must ask before deleting files, modifying credentials, or running destructive co

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 73)May include surrounding context.

md
**Additional guardrails:**
- Supervisor Protocol (`references/supervisor-prompt.md`) requires the coding-agent to ask before deleting files or modifying credentials
- PM scans coding-agent output for dangerous patterns (`rm -rf`, `DROP TABLE`, `chmod 777`, `--force`, `--no-verify`, credential file modifications)
- Human-in-the-loop: plan approval gate before execution begins, decision escalation during execution
- Skill is user-invocable only — only runs when you explicitly send `/dev <request>`

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
**Additional guardrails:**
- Supervisor Protocol (`references/supervisor-prompt.md`) requires the coding-agent to ask before deleting files or modifying credentials
- PM scans coding-agent output for dangerous patterns (`rm -rf`, `DROP TABLE`, `chmod 777`, `--force`, `--no-verify`, credential file modifications)
- Human-in-the-loop: plan approval gate before execution begins, decision escalation during execution
- Skill is user-invocable only — only runs when you explicitly send `/dev <request>`

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

md
**Additional guardrails:**
- Supervisor Protocol (`references/supervisor-prompt.md`) requires the coding-agent to ask before deleting files or modifying credentials
- PM scans coding-agent output for dangerous patterns (`rm -rf`, `DROP TABLE`, `chmod 777`, `--force`, `--no-verify`, credential file modifications)
- Human-in-the-loop: plan approval gate before execution begins, decision escalation during execution
- Skill is user-invocable only — only runs when you explicitly send `/dev <request>`

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 382)May include surrounding context.

md
**Additional guardrails:**
- Supervisor Protocol (`references/supervisor-prompt.md`) requires the coding-agent to ask before deleting files or modifying credentials
- PM scans coding-agent output for dangerous patterns (`rm -rf`, `DROP TABLE`, `chmod 777`, `--force`, `--no-verify`, credential file modifications)
- Human-in-the-loop: plan approval gate before execution begins, decision escalation during execution
- Skill is user-invocable only — only runs when you explicitly send `/dev <request>`

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The skill creates persistent worktrees under ~/.worktrees/$TASK, outside the normal workspace boundary, and stores task state across independent sessions. This increases data-retention and cross-project exposure risk, especially if sensitive code or artifacts remain on disk after interruption or context loss.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
# Detect base branch
BASE=$(git -C <project-dir> rev-parse --abbrev-ref HEAD)

# Create worktree
TASK=<task-name>  # 2-3 words, kebab-case, from request
git -C <project-dir> worktree add ~/.worktrees/$TASK -b feat/$TASK

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the PM to relay user feedback verbatim into a privileged downstream coding-agent session running with --dangerously-skip-permissions. That creates a natural-language injection and data-leakage channel where a user may unintentionally or maliciously include secrets, credentials, or instructions that alter the behavior of the privileged agent.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Forwarding [DECISION_NEEDED] answers verbatim into the resumed coding-agent session creates the same unsanitized disclosure and prompt-injection pathway during execution. Because this occurs after approval and inside a resumed privileged session, the downstream impact can include risky actions based on manipulated or overly broad user responses.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The instruction to auto-approve 'small scope' nested plans allows the coding-agent to expand work during execution without renewed human authorization. In a privileged coding workflow, even a seemingly small sub-plan can introduce dependency changes, data handling, or file modifications beyond the user's approved intent.

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

md
### 4. Nested plans

If coding-agent needs a sub-plan during execution:
- Small scope (< 3 steps) -> auto-approve, let coding-agent continue
- Large scope (new feature, architecture change) -> pause, report to user for approval

### 5. Dangerous pattern detection

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

The acceptance-testing guidance directs the agent/PM to interact with live endpoints, start servers, take screenshots, and run example commands, which can transmit project data externally or trigger network side effects. In this skill's context, testing is expected, but the lack of explicit scoping to local/staging environments and no outbound-network restrictions makes accidental external exposure plausible.

Content

Scanner excerpt · SKILL.md (reported line 262)May include surrounding context.

Layer 2: Functional integration tests (by project type)

text
API project     -> curl key endpoints, verify response status and format
Web/UI project  -> start dev server, screenshot key pages (if headless browser available)
CLI project     -> run example commands from README
Library project -> run examples/ sample code

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The skill explicitly requires disabling workspaceOnly and notes that --dangerously-skip-permissions may override tool restrictions, materially weakening platform isolation. This broadens the accessible filesystem and allows the downstream agent to operate beyond the intended sandbox, making any prompt injection or agent error significantly more dangerous.

Content

Scanner excerpt · SKILL.md (reported line 375)May include surrounding context.

md
This skill requires two platform-level changes to function:

1. **`tools.fs.workspaceOnly = false`** — Git worktrees are created at `~/.worktrees/<task>/`, outside the OpenClaw workspace. Without this setting, the agent cannot read/write worktree files. This is a session-level OpenClaw config change; re-enable it when not using coding-pm on sensitive systems.

2. **`--dangerously-skip-permissions`** — Claude Code requires this flag for non-interactive (background) execution where no TTY is available for permission prompts. This is the standard approach for any Claude Code automation (CI/CD, scripts, background agents). All `claude` invocations also use `--output-format json` for structured, parseable output. **Note:** `--dangerously-skip-permissions` may override `--allowedTools` restrictions — the planning phase tool restriction is a best-effort guardrail, not a hard sandbox. The Supervisor Protocol and PM monitoring provide additional enforcement.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The /task cancel workflow performs destructive cleanup, including force-deleting the feature branch, without requiring an explicit confirmation step or warning the operator about irreversibility. In a multi-task automation skill, accidental invocation or misunderstanding can cause loss of unmerged work and forensic context.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/supervisor-prompt.md (reported line 28)May include surrounding context.

md
- Apply YAGNI: remove anything not directly needed.

### Test-Driven Development
- If the project has an existing test suite, follow TDD: write failing test -> minimal code -> pass -> refactor.
- If no test framework exists, propose adding one in the plan. If declined, skip TDD but verify behavior manually.
- If a test passes immediately without new code, the test is wrong — fix it.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The prompt instructs the agent to invoke an external command (openclaw system event) and, on failure, write a local marker file to .supervisor/wake-marker. These actions extend beyond passive project-management guidance into tool-triggering and filesystem signaling, creating an unnecessary side effect channel that could be abused to exfiltrate task state, trigger unintended supervisor behavior, or interact with host capabilities not required for code planning/review. In this skill context, the danger is elevated because the prompt is explicitly designed to orchestrate background coding activity and supervisor wake-ups, so the command is likely to be executed automatically.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.