Back to skill

Security audit

local-coding-orchestrator

Security checks for vulnerabilities and agentic risk

Overview

The skill’s purpose is coherent, but it tells users to auto-launch local PowerShell worker scripts that are missing from the package and referenced through unsafe relative commands.

Install only if you intentionally want a local coding-agent orchestrator. Do not run the PowerShell examples as written unless you have verified the scripts from a trusted installed path; avoid ExecutionPolicy Bypass, prefer preview/manual modes first, isolate the target repo or worktree, and treat generated prompts/logs/results as potentially sensitive local artifacts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
docs/usage-guide.md:48
Finding

PowerShell Execution-Policy Bypass Combined with Relative Script Resolution

Content
View full analysis

Vulnerability Details

File Location: docs/usage-guide.md:48-84; docs/operator-playbook.md:17-34
Vulnerability Type: Unsafe PowerShell execution configuration and relative script path resolution
Risk Level: Medium

Vulnerable Code

docs/usage-guide.md:48-84:

powershell
powershell -ExecutionPolicy Bypass -File assets/scripts/task-state.ps1 \
  -Action init -TaskId feat-demo -Repo D:/data/code/my-repo -TaskType feature \
  -Pipeline implement_and_review -Role implementer -Agent codex
powershell
powershell -ExecutionPolicy Bypass -File assets/scripts/task-state.ps1 \
  -Action transition -TaskId feat-demo -ToState queued -Reason "ready" -Actor supervisor
powershell
powershell -ExecutionPolicy Bypass -File assets/scripts/supervise-task.ps1 \
  -TaskId feat-demo -AutoLaunch -ApplyTransition -Json
powershell
powershell -ExecutionPolicy Bypass -File assets/scripts/supervise-task.ps1 \
  -TaskId feat-demo -AutoLaunch -AutoProbe -ApplyTransition -Json
powershell
powershell -ExecutionPolicy Bypass -File assets/scripts/reconcile-worker.ps1 \
  -TaskId feat-demo -Json
powershell
powershell -ExecutionPolicy Bypass -File assets/scripts/supervise-task.ps1 \
  -TaskId feat-demo -Json

docs/operator-playbook.md:17-34:

powershell
powershell -ExecutionPolicy Bypass -File assets/scripts/supervise-task.ps1 \
  -TaskId feat-demo -AutoLaunch -AutoProbe -ApplyTransition -Json
powershell
powershell -ExecutionPolicy Bypass -File assets/scripts/reconcile-worker.ps1 \
  -TaskId feat-demo -Json
powershell
powershell -ExecutionPolicy Bypass -File assets/scripts/supervise-task.ps1 \
  -TaskId feat-demo -Json

Technical Analysis

The documented operational workflow explicitly starts PowerShell with -ExecutionPolicy Bypass. This suppresses execution-policy enforcement for the launched PowerShell process, ...[truncated 2936 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove -ExecutionPolicy Bypass from all documented commands. Use the host's configured execution policy rather than disabling it for routine operation.
  2. Ship the referenced scripts as part of the package before documenting them as executable components.
  3. Resolve scripts from a trusted absolute installation path instead of the current working directory. For example, have a trusted launcher determine the canonical skill directory and construct a fully qualified script path.
  4. Before execution, canonicalize the script path and verify that it remains within the expected skill installation directory.
  5. Sign distributed PowerShell scripts and configure environments to require an appropriate signature policy where operationally feasible.
  6. Publish checksums or package-integrity metadata and verify them before first execution or after updates.
  7. Restrict write access to the installed skill and script directories so ordinary project content cannot replace orchestration scripts.
  8. Fail closed when a required script is missing. Do not search alternate working directories or silently accept a same-named replacement.
  9. If a narrowly scoped policy override is operationally unavoidable, document the reason, require explicit operator confirmation, verify the script's signature or hash first, and limit the override to a trusted absolute file.
  10. Correct the examples to use valid PowerShell line continuation syntax where applicable, reducing the likelihood that operators rewrite the commands into less controlled forms.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 673)May include surrounding context.

md
1. update `SKILL.md` and bundled scripts

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly assumes it can launch local coding CLIs, create working directories, keep artifacts on disk, and run background processes, but it does not prominently require informed user consent before doing so. In a local coding/repo context, that can lead to unexpected code execution, repository modification, or persistence of potentially sensitive task artifacts and logs on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The quick-start directs operators to run supervise-task.ps1 with automatic worker launch, including optional probing, without a nearby warning that these actions may immediately execute local scripts, invoke external coding agents, and alter the target repository or worktree. Because this is an operational section intended for direct use, omission of a clear execution/modification warning materially increases the chance of unreviewed local execution.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
70% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · docs/usage-guide.md (reported line 40)May include surrounding context.

md
1. create/init a task record
2. move it to `queued`
3. let supervisor auto-launch a background worker
4. reconcile worker state periodically
5. let supervisor recommend `awaiting-review`, `blocked`, or `completed`
6. use retry briefs only when the failure is semantic rather than environmental

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file documents execution-mode behavior including calling the actual tool wrapper, capturing raw output into logs, writing result files, updating task metadata, and a future automatic supervisor-triggered launch. While the behavior is described, it does not clearly warn users about potential effects on local files, logs, or automatic execution, which is the kind of user-facing disclosure expected for markdown under this rule.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.