Back to skill

Security audit

cron-orchestration

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed cron-orchestration specification, but it grants broad automated write, push, notification, and agent-dispatch authority without enough safeguards.

Install or invoke this only in a repository where automated cron agents are allowed to modify files, notify people, and push to the remote. Before use, add explicit review gates or branch isolation for git push, confirm no secrets can be published, fix dependency enforcement, and disable or separate the older side_research_run.sh flow to avoid overlapping automation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill mandates immediate git commit and push of task outputs but does not prominently warn users that running it will modify and publish changes to a remote repository. In an automated orchestration context, this increases the risk of unintended data disclosure, propagation of bad outputs, or irreversible changes if tasks process sensitive or unreviewed content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill claims dependency-aware execution, but the documented validation result explicitly states dependent tasks were still executed in the same round. In a cron orchestration skill, violating dependency ordering can cause tasks to run on incomplete or invalid inputs, producing incorrect outputs, premature notifications, and unintended downstream actions such as commits or pushes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
61% confidence
Finding

The mutual exclusion section documents a 5-minute lock preventing concurrent or near-concurrent runs. The execution log shows a run at 13:05 and another manual trigger at 13:49, which is outside 5 minutes, so this is not itself contradictory; however, the file provides no concrete evidence of lock cleanup or enforcement beyond the claim. Because the timing does not directly violate the rule, this is only weakly indicative and should not be treated as a strong mismatch.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.