Back to skill

Security audit

Claude Code Runner

Security checks for vulnerabilities and agentic risk

Overview

This skill’s goal is clear, but it runs Claude Code with broad local authority and has concrete unsafe paths for automatic approvals, command injection, and privileged file write-back.

Review this carefully before installing. It is not just a helper script: it can run agent-driven coding tasks, auto-approve prompts, and write changes back to your source tree. Only use it in a disposable or tightly controlled environment, avoid running it with root privileges, and do not pass untrusted prompts or project directories until the shell construction and symlink-safe sync issues are fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run_claude.py:61
Finding

Shell Command Injection Through the Prompt and Working Directory

Content
View full analysis
&1' ] ``` ### Technical Analysis The `prompt` and `temp_workdir` values are interpolated directly into a command string passed to `su -c`. Although `subprocess.Popen` later receives an argument list, the command supplied after `su -c` is explicitly interpreted by a shell. Double quotes around `prompt` do not prevent shell injection. A prompt containing a double quote followed by shell control operators can terminate the intended argument and append a new command. For example, a value shaped like `" ; attacker_command ; #` would cause the shell to execute `attacker_command`. The working directory is similarly unsafe because `temp_workdir` is inserted after `cd` without shell quoting. Its final component is derived from the basename of the caller-supplied `workdir`, so a directory name containing shell metacharacters may alter the command. ### Attack Path 1. An attacker gains control over, or influences, the `prompt` argument passed through the CLI or Python API. Alternatively, the attacker supplies a project directory whose basename contains shell metacharacters. 2. The runner embeds the controlled value into the `su -c` command string without safe quoting. 3. The shell launched by `su` parses the injected quotation marks and command separators. 4. The injected command executes under the selected target account. 5. The attacker can read or modify any resources accessible to that account and can potentially manipulate the temporary project so that privileged synchronization performs additional unsafe operations. ### Impact Assessment Successful exploitation provides arbitrary command execution with the privileges of the acc ...[truncated 530 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/run_claude.py:130
Finding

Privileged File Disclosure or Overwrite Through Symlink-Following Synchronization

Content
View full analysis
os.path.getmtime(target_file): print(f"[SYNC] Updated: {os.path.join(rel_path, file) if rel_path != '.' else file}", file=sys.stderr) shutil.copy2(source_file, target_file) ``` ### Technical Analysis Claude and any commands it launches operate as the selected non-root user and can modify the temporary project tree. After a successful exit, `_sync_changes` is called by the original wrapper process, which is expected to have elevated privileges because the wrapper performs ownership changes and user switching. The synchronization routine does not use `lstat`, reject symbolic links, or verify that resolved source and destination paths remain beneath their approved roots. `shutil.copy2` follows symbolic links by default. Two relevant exploitation modes result: - **Source-link disclosure:** A controlled symbolic link in the temporary project can point to a file readable by the privileged wrapper but not by the selected user. During synchronization, the privileged ...[truncated 2008 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run_claude.py:92
Finding

Overbroad Automatic Approval of Interactive Prompts

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (15)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The overview states that the wrapper automatically responds to confirmation prompts, but it does not present this as a prominent safety warning to users. Auto-confirming prompts can bypass human review for sensitive actions such as code modification, command execution, or destructive operations that would normally require explicit approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes file synchronization as a feature but does not clearly warn that changes made in a temporary workspace are synced back into the original directory. This can lead to silent modification of user code or data, potentially overwriting files, introducing malicious or unsafe changes, or corrupting repositories without adequate user awareness.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/run_claude.py (reported line 54)May include surrounding context.

python
master_fd, slave_fd = pty.openpty()
        
        # Set environment variables
        env = os.environ.copy()
        env['TERM'] = 'xterm-256color'
        env['HOME'] = f'/home/{user}'

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code watches PTY output and automatically sends 'y' when it detects generic confirmation language like 'proceed' or 'continue'. In this context, that can authorize downstream actions initiated by Claude or invoked tools without any human review, including file changes, command execution, or other sensitive operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README explicitly advertises automatic confirmation of prompts and automatic synchronization of file changes back to the original directory, but it does not prominently warn that the tool can make and persist autonomous modifications. In the context of an agent skill that executes coding tasks, this increases the risk of unintended destructive edits, unsafe approvals, or propagation of malicious changes initiated by prompts or tool behavior.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 90)May include surrounding context.

md
- Python 3.8+
- Claude Code (installed and in PATH)
- Unix-like environment (Linux/macOS)
- root or sudo privileges (for user switching)

## How It Works

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises and relies on powerful capabilities including shell execution, environment access, and file read/write, but it declares no explicit tool scope or permissions boundary. This is dangerous because consumers and orchestration systems cannot easily constrain what the skill may do, increasing the chance of unintended command execution, file modification, or secret exposure.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
84% confidence
Finding

Requiring root or sudo access for user switching materially increases the blast radius of any mistake or compromise in the skill's execution path. In combination with shell execution, auto-confirmation, and file synchronization, elevated privileges could allow unauthorized file ownership changes, broader filesystem modification, or privilege misuse.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
- Python 3.8+
- Claude Code installed and in PATH
- Unix-like environment (Linux/macOS)
- Root or sudo access (for user switching)

## Configuration

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
84% confidence
Finding

The limitation reiterates that root/sudo may be required, confirming that elevated execution is an expected deployment mode rather than an edge case. This makes the skill more dangerous in context because its other behaviors—automatic prompt responses and syncing modifications back—become significantly riskier when performed with privileged access.

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

md
## Limitations

- Requires Unix-like environment (uses PTY)
- Requires root/sudo for user switching
- Claude Code must be installed separately
- May not handle all edge cases of interactive prompts

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest uses "-en" in the skill name and labels the skill as an "English version," which implies a language restriction. There is no indication that users can choose another language or that the English-only constraint is required for a documented region- or policy-specific reason.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/run_claude.py (reported line 67)May include surrounding context.

python
print(f"[INFO] Starting Claude Code task...", file=sys.stderr)
        
        # Start process
        process = subprocess.Popen(
            cmd,
            stdin=slave_fd,
            stdout=slave_fd,

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/run_claude.py (reported line 73)May include surrounding context.

python
stdout=slave_fd,
            stderr=slave_fd,
            env=env,
            preexec_fn=os.setsid
        )
        
        os.close(slave_fd)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This prompt-bypass behavior suppresses an intended safety checkpoint and enables potentially destructive actions to proceed automatically. Because the runner is specifically designed to execute coding tasks through an agent, the lack of approval gating materially increases the risk of unauthorized modifications or command side effects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

On successful execution, the runner automatically syncs files from the temporary workspace back into the original project directory. In this skill context, Claude is being asked to perform arbitrary programming tasks, so this creates an unguarded write-back path that can persist unintended or unsafe modifications to the caller's source tree.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Writing generated changes back into the original working directory without a warning or confirmation step removes a key review barrier. In an agent-runner skill, this is particularly risky because the model's output becomes persisted project state automatically, potentially introducing malicious or low-quality code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.