Back to skill

Security audit

Compiling Architecture

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed architecture-compilation workflow with normal local file and terminal use, but users should verify the external compiler checkout and dependencies before running setup commands.

Before installing or using this skill, verify the arch-compiler repository source and commit, review its requirements file, install dependencies in a virtual environment or container, and avoid running pip with elevated privileges. Treat compiler-maintenance actions, especially vocabulary changes and new patterns, as review-required changes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:471
Finding

Unverified Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 471–472
Vulnerability Type: Supply-chain risk from installing unaudited external dependencies
Risk Level: Medium

Vulnerable Code

bash
# Install dependencies
python3 -m pip install -r ~/.codex/arch-compiler/tools/requirements.txt

Technical Analysis

The skill instructs the agent to install Python packages from a requirements file in a separately installed compiler repository. That requirements file is not included in the audited project, so its package names, sources, version constraints, and integrity controls could not be verified.

The command does not visibly enforce exact versions, package hashes, a trusted package index, or binary-only installation. Depending on the external requirements file and pip configuration, installation can retrieve mutable or compromised distributions and execute package build or installation logic with the privileges of the agent's operating-system account.

This is a supply-chain trust-boundary weakness. The documented compiler repository, its requirements file, the configured Python package index, and all resolved transitive dependencies must be trusted even though they are outside the reviewed artifact.

Attack Path

  1. An attacker compromises the separately installed architecture-compiler repository, alters its tools/requirements.txt, publishes a malicious dependency version, or exploits dependency confusion through an unsafe package source.
  2. An agent follows the skill instructions and executes:
    bash
    python3 -m pip install -r ~/.codex/arch-compiler/tools/requirements.txt
    
  3. Pip resolves and downloads the attacker-controlled package or compromised release.
  4. Malicious build or installation code executes under the agent user's account.
  5. The payload can access files, credentials, environment variables, and repositories available to that account and can perform further actions within those privileges.

Impact Ass

...[truncated 594 chars]

Remediation
View remediation

Remediation Suggestions

  1. Include an audited dependency lock file with the skill or pin the compiler to a reviewed immutable release.
  2. Pin every direct and transitive dependency to an exact version.
  3. Record cryptographic hashes and install with hash verification:
    bash
    python3 -m pip install --require-hashes -r requirements.lock
    
  4. Explicitly configure an approved package index and disable untrusted supplemental indexes to reduce dependency-confusion exposure.
  5. Verify the compiler checkout against a trusted commit hash or signed release before reading its requirements.
  6. Install dependencies in a dedicated virtual environment or disposable, least-privilege container rather than the user's global Python environment.
  7. Prefer prebuilt, verified wheels where feasible to reduce arbitrary build-time execution.
  8. Add automated dependency scanning and periodic lock-file review before approving dependency updates.
  9. Document that installation must not be run with sudo or an administrative account.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
2. Read this `SKILL.md` for the task-specific workflow.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The repo contract says tools/, schemas/, config/, scripts/, and patterns/ are read-only for agents, reinforced again at L045. However, the new-pattern workflow later tells agents to update schemas/capability-vocabulary.yaml when introducing a new capability, which directly contradicts the earlier read-only rule for schemas/. This is an active documentation contradiction about whether agents may modify schema content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L046 frames the skill as only for turning inputs into approved architecture artifacts, not implementation work. Later sections 'Adding or Editing Patterns' and 'Authoring a new pattern' instruct agents to perform compiler-maintenance tasks inside the compiler ecosystem, including authoring pattern files and updating schema vocabulary. That is a contradictory expansion of purpose within the same skill documentation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
The important split is:
- `AGENTS.md` = global agent rules for this repo
- `skills/using-arch-compiler/SKILL.md` = workflow router
- `skills/compiling-architecture/SKILL.md` = how to compile and finalise architecture
- `skills/implementing-architecture/SKILL.md` = how to implement an already-approved architecture

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
The important split is:
- `AGENTS.md` = global agent rules for this repo
- `skills/using-arch-compiler/SKILL.md` = workflow router
- `skills/compiling-architecture/SKILL.md` = how to compile and finalise architecture
- `skills/implementing-architecture/SKILL.md` = how to implement an already-approved architecture

---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
- `AGENTS.md` = global agent rules for this repo
- `skills/using-arch-compiler/SKILL.md` = workflow router
- `skills/compiling-architecture/SKILL.md` = how to compile and finalise architecture
- `skills/implementing-architecture/SKILL.md` = how to implement an already-approved architecture

---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 452)May include surrounding context.

md
- `AGENTS.md` = global agent rules for this repo
- `skills/using-arch-compiler/SKILL.md` = workflow router
- `skills/compiling-architecture/SKILL.md` = how to compile and finalise architecture
- `skills/implementing-architecture/SKILL.md` = how to implement an already-approved architecture

---

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 477)May include surrounding context.

md
# Compile to stdout
python3 ~/.codex/arch-compiler/tools/archcompiler.py my-spec.yaml

# Compile + write artifact files (output directory must exist before running)
mkdir -p compiled_output/
python3 ~/.codex/arch-compiler/tools/archcompiler.py my-spec.yaml -o compiled_output/

Static analysis

No suspicious patterns detected.