Back to skill

Security audit

conclave

Security checks for vulnerabilities and agentic risk

Overview

Conclave is a disclosed multi-agent debate tool, but it should be reviewed because it can change global tools, use third-party AI endpoints, and persist or duplicate full debate records.

Install only after reviewing the operational impact. Prefer --check-only and --skip-update, pin or manually review CLI versions, use official provider endpoints unless you intentionally choose a relay, avoid sensitive or regulated topics, run from a private non-synced directory, and periodically delete both ~/.hermes/debates archives and exported copies.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/preflight.sh:53
Finding

Mandatory Unpinned Global CLI Updates Create a Mutable Remote Execution Path

Content
View full analysis
/dev/null 2>&1 && have "$2"; then ``` ### Technical Analysis Preflight is documented as mandatory before every debate, but its default behavior globally updates several executable AI clients. Versions and integrity hashes are not pinned, and some update operations are delegated to each CLI's own update mechanism. Commands such as `npm install -g ...@latest` retrieve executable code whose contents can change after this Skill has been reviewed. NPM packages may also execute lifecycle scripts during installation. The affected binaries are then invoked during the same preflight run, creating a direct retrieval-to-execution chain. Global installation increases impact because the changed binaries remain available to other sessions and projects. Suppressing installer output also reduces the user's ability to identify unexpected lifecycle behavior or dependency changes. ### Attack Path 1. An upstream package, transitive dependency, maintainer account, registry response, or CLI update channel is compromised. 2. A malicious release becom ...[truncated 1058 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:376
Finding

Skill Instructions Recommend a Nested-Shell Pattern That Can Execute Debate Content as Shell Code

Content
View full analysis
"'` ``` ### Technical Analysis The Skill correctly recognizes that prompt content can contain shell metacharacters, but then recommends using double-quoted shell expansion to place file contents inline. This is unsafe when the resulting string is passed to another shell through `zsh -i -c` or `bash -i -c`. In a nested-shell construction, text read from a debate file can become part of the command string parsed by the inner shell. Content containing quote termination, command substitution, redirection, separators, or newline-delimited shell syntax can therefore escape the intended prompt argument. Removing only backticks is not sufficient. Other syntax—including `$(...)`, quotes, semicolons, redirections, and shell expansions—can produce equivalent injection effects. Debate briefs are derived from user-provided topics and context, while later rounds also include outputs from external models, so this content must be treated as untrusted. ### Attack Path 1. An attacker places shell sy ...[truncated 1169 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/panelists.md:26
Finding

Configuration Directs Codex Traffic and Credentials to a Third-Party Relay Not Disclosed Consistently

Content
View full analysis
'` For important sessions, replace medium with xhigh. - Auth: cmdme.cn relay, sk- key in `~/.codex/auth.json`; in config.toml set `requires_openai_auth = false`, `wire_api = "responses"`, `base_url = "https://cmdme.cn"`. ``` Gemini is also documented as supporting the same relay: ```markdown - Auth / env: `GOOGLE_GEMINI_BASE_URL` + `GEMINI_API_KEY` (persisted in user shell rc). Key format determines provider: `AQ.Ab8…` = Google official (base generativelanguage.googleapis.com), `sk-…` = cmdme relay. Mixing them causes 401. ``` However, the public privacy description states: ```markdown - **Data leaves your machine**: Prompts are sent to Claude (Anthropic), Codex (OpenAI), Gemini (Google), and Qwen (Alibaba) cloud APIs. ``` ### Technical Analysis The panelist reference directs Codex users to configure `https://cmdme.cn` as the API base URL and disable normal OpenAI authentication behavior. As the TLS endpoint, that relay necessarily receives the request authorization material and debate prompts in plaintext at the application layer. This destination is materially different from the README's representation that Codex prompts are sent to OpenAI. Users relying on the primary privacy notice may therefore consent to the wrong data recipient. Debate prompts can contain business plans, legal analysis, personal information, internal constraints, and other sensitive context. Setting `no_proxy='*'` also forces a direct connection rather than allowing a configured organizational proxy to enforce egress policy, logging, filtering, or de ...[truncated 1083 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/panelists.md:13
Finding

Instructions Unlock the Entire macOS Login Keychain for One CLI Credential

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:313
Finding

Mandatory Full-Arena Export Duplicates Sensitive Debate Records into an Uncontrolled Working Directory

Content
View full analysis
"$PWD/" diff -r ~/.hermes/debates/conclave-YYYYMMDD- "$PWD/conclave-YYYYMMDD-" && echo "COPY VERIFIED" ``` - The diff verification is mandatory; report file count, total size, and the destination absolute path. - `~/.hermes/debates/` remains the canonical archive; the working-directory copy is the user's working artifact. - If the user only asks for "the results", still export the full arena — briefs, round sources, verdicts, and votes are all part of the deliverable. - **Security warning**: the exported arena contains the full raw debate content (briefs, agent outputs, mapping). Do not run Conclave inside directories that are auto-synced to public repositories, cloud backups, or shared drives unless you want that content synchronized. ``` ### Technical Analysis The Skill mandates copying the complete debate arena to `$PWD`, even when the user asks only for final results. The exported material includes the original brief, constraints, raw model outputs, anonymity mapping, votes, and intermediate verdicts. The working directory is not validated before copying. It may be a Git repository, cloud-synchronized folder, shared workspace, mounted network location, CI artifact directory, or publicly served directory. The Skill recognizes this risk in a warning but still makes full export mandatory and preserves a second canonical copy indefinitely. Disclosure does not remove the unsafe default: data minimization would export only re ...[truncated 1158 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Beyond debate coordination, the skill performs updates, health checks, logging, and network-dependent CLI execution. Undeclared operational behaviors are dangerous because users may authorize a low-risk reasoning tool while actually granting a workflow that changes software state, writes local records, and initiates external communications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Beyond debate coordination, the skill performs updates, health checks, logging, and network-dependent CLI execution. Undeclared operational behaviors are dangerous because users may authorize a low-risk reasoning tool while actually granting a workflow that changes software state, writes local records, and initiates external communications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Beyond debate coordination, the skill performs updates, health checks, logging, and network-dependent CLI execution. Undeclared operational behaviors are dangerous because users may authorize a low-risk reasoning tool while actually granting a workflow that changes software state, writes local records, and initiates external communications.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
99% confidence
Finding

The skill advertises installing and updating global CLI tools and performing pre-flight self-updates. Self-modification and package installation are high-risk because they change the host environment, may introduce supply-chain exposure, and exceed what users typically expect from a reasoning skill.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
This skill does **significantly more** than "debate orchestration". By design it:

- **Installs and updates global CLI tools** (`npm install -g`, brew, apt, etc.) via `scripts/install.sh` and pre-flight self-updates.
- **Inspects local auth state** (checks for API keys, OAuth tokens, keychain status) without reading secret values.
- **Transmits your debate topic** to 6 third-party AI cloud APIs (Claude/OpenAI, Google, Alibaba, ByteDance/Ark, Manus).
- **Persists full debate records** indefinitely under `~/.hermes/debates/` (briefs, raw agent outputs, verdicts, votes).

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

The preflight workflow includes best-effort self-updates of panelist CLIs before running debates. Even if framed as convenience, automatic update behavior can unpredictably alter execution, break reproducibility, or pull malicious upstream changes into the environment without focused user review.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
2. **Fill the brief**: write brief.md, mapping.md, and constraints.md under `01_brief/`.
3. **Version & parameter check**: see `references/panelists.md` (commands, parameters, auth pitfalls for each agent).
4. **Pre-flight (update + ignition)**: run `bash ~/.hermes/skills/conclave/scripts/preflight.sh <arena-path>`
   - Phase A: best-effort self-update of all panelist CLIs (failures are non-fatal and logged; `--skip-update` bypasses).
   - Phase B: ignition ping of all panelist agents (plus Manus, verified manually); results are auto-written to `00_preflight/preflight.log`.
   - Any ping failure: fix first (key / proxy / version), then debate.
5. **Launch the debate**: use `terminal(background=true)` to spawn the panelist CLIs in parallel, writing outputs to `02_r1/`.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · references/consensus-protocol-v1.md (reported line 123)May include surrounding context.

md
Every debate appends one JSONL record per **verifiable** prediction to `~/.hermes/debates/calibration.jsonl` with fields: prediction_id, question, timestamp, agent, role, probability, resolution_date, ground_truth (filled at resolution), brier_score, log_loss. Only predictions with a defined check date and an observable outcome are recorded. A cron job (or the chair at the next debate) resolves due predictions.

**Dual-track rule [POLICY]**: Track A = verifiable predictions → scored. Track B = strategic judgments ("this strategy is good") → never auto-scored; only post-hoc qualitative review. The system must never refuse hard strategic questions just because they are unscoreable.

## 11a. Research definitions (do NOT implement) [EXPERIMENTAL]

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/panelists.md (reported line 14)May include surrounding context.

  • Command: no_proxy='*' claude -p '<prompt>' --max-turns 1
  • Auth: official OAuth (zhang@testsprite.com), credentials stored in macOS login keychain. Background sessions may fail to read the keychain (security exit 36). DO NOT put passwords in prompts or scripts. The user must manually unlock the keychain in an interactive terminal before starting a background debate session (macOS only; N/A on Linux/Windows where only ~/.claude/.credentials.json is checked):
    text
    security unlock-keychain ~/Library/Keychains/login.keychain-db
    

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/panelists.md (reported line 15)May include surrounding context.

  • Command: no_proxy='*' claude -p '<prompt>' --max-turns 1
  • Auth: official OAuth (zhang@testsprite.com), credentials stored in macOS login keychain. Background sessions may fail to read the keychain (security exit 36). DO NOT put passwords in prompts or scripts. The user must manually unlock the keychain in an interactive terminal before starting a background debate session (macOS only; N/A on Linux/Windows where only ~/.claude/.credentials.json is checked):
    text
    security unlock-keychain ~/Library/Keychains/login.keychain-db
    

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/panelists.md (reported line 17)May include surrounding context.

  • Command: no_proxy='*' claude -p '<prompt>' --max-turns 1
  • Auth: official OAuth (zhang@testsprite.com), credentials stored in macOS login keychain. Background sessions may fail to read the keychain (security exit 36). DO NOT put passwords in prompts or scripts. The user must manually unlock the keychain in an interactive terminal before starting a background debate session (macOS only; N/A on Linux/Windows where only ~/.claude/.credentials.json is checked):
    text
    security unlock-keychain ~/Library/Keychains/login.keychain-db
    

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 186)May include surrounding context.

sh
- Command: `no_proxy='*' claude -p '<prompt>' --max-turns 1`
- Auth: official OAuth (zhang@testsprite.com), credentials stored in macOS login keychain.
  Background sessions may fail to read the keychain (security exit 36).
  **DO NOT put passwords in prompts or scripts.** The user must manually unlock the keychain in an interactive terminal before starting a background debate session (macOS only; N/A on Linux/Windows where only `~/.claude/.credentials.json` is checked):
  ```
  security unlock-keychain ~/Library/Keychains/login.keychain-db

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 187)May include surrounding context.

sh
- Command: `no_proxy='*' claude -p '<prompt>' --max-turns 1`
- Auth: official OAuth (zhang@testsprite.com), credentials stored in macOS login keychain.
  Background sessions may fail to read the keychain (security exit 36).
  **DO NOT put passwords in prompts or scripts.** The user must manually unlock the keychain in an interactive terminal before starting a background debate session (macOS only; N/A on Linux/Windows where only `~/.claude/.credentials.json` is checked):
  ```
  security unlock-keychain ~/Library/Keychains/login.keychain-db

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/panelists.md (reported line 15)May include surrounding context.

  • Command: no_proxy='*' claude -p '<prompt>' --max-turns 1
  • Auth: official OAuth (zhang@testsprite.com), credentials stored in macOS login keychain. Background sessions may fail to read the keychain (security exit 36). DO NOT put passwords in prompts or scripts. The user must manually unlock the keychain in an interactive terminal before starting a background debate session (macOS only; N/A on Linux/Windows where only ~/.claude/.credentials.json is checked):
    text
    security unlock-keychain ~/Library/Keychains/login.keychain-db
    

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/panelists.md (reported line 19)May include surrounding context.

  • Command: no_proxy='*' claude -p '<prompt>' --max-turns 1
  • Auth: official OAuth (zhang@testsprite.com), credentials stored in macOS login keychain. Background sessions may fail to read the keychain (security exit 36). DO NOT put passwords in prompts or scripts. The user must manually unlock the keychain in an interactive terminal before starting a background debate session (macOS only; N/A on Linux/Windows where only ~/.claude/.credentials.json is checked):
    text
    security unlock-keychain ~/Library/Keychains/login.keychain-db
    

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 176)May include surrounding context.

sh
- Command: `no_proxy='*' claude -p '<prompt>' --max-turns 1`
- Auth: official OAuth (zhang@testsprite.com), credentials stored in macOS login keychain.
  Background sessions may fail to read the keychain (security exit 36).
  **DO NOT put passwords in prompts or scripts.** The user must manually unlock the keychain in an interactive terminal before starting a background debate session (macOS only; N/A on Linux/Windows where only `~/.claude/.credentials.json` is checked):
  ```
  security unlock-keychain ~/Library/Keychains/login.keychain-db
  ```

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/panelists.md (reported line 17)May include surrounding context.

Background sessions may fail to read the keychain (security exit 36). DO NOT put passwords in prompts or scripts. The user must manually unlock the keychain in an interactive terminal before starting a background debate session (macOS only; N/A on Linux/Windows where only ~/.claude/.credentials.json is checked):

text
security unlock-keychain ~/Library/Keychains/login.keychain-db

If still 401: check for and move aside old ~/.claude/.credentials.json, then retry.

  • Update: claude update

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 187)May include surrounding context.

sh
Background sessions may fail to read the keychain (security exit 36).
  **DO NOT put passwords in prompts or scripts.** The user must manually unlock the keychain in an interactive terminal before starting a background debate session (macOS only; N/A on Linux/Windows where only `~/.claude/.credentials.json` is checked):
  ```
  security unlock-keychain ~/Library/Keychains/login.keychain-db
  ```
  If still 401: check for and move aside old `~/.claude/.credentials.json`, then retry.
- Update: `claude update`

Chaining Abuse

High
Category
Tool Misuse
Confidence
84% confidence
Finding

Chaining sudo apt-get update with sudo apt-get install couples repository refresh and privileged installation into one automated flow, reducing opportunities for user inspection or partial failure handling. This is not malicious by itself, but it increases the blast radius of a setup script run with elevated privileges.

Content

Scanner excerpt · scripts/install.sh (reported line 83)May include surrounding context.

sh
linux|wsl)
      if have apt-get; then
        info "installing node via apt-get (may prompt for sudo password)..."
        sudo apt-get update -qq && sudo apt-get install -y nodejs npm
      elif have dnf; then
        info "installing node via dnf (may prompt for sudo password)..."
        sudo dnf install -y nodejs npm

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The --noconfirm flag weakens safeguards on a privileged package-management command, making it easier for the script to apply system changes without user review. In setup tooling, this creates avoidable risk even if the intended package names are benign.

Content

Scanner excerpt · scripts/install.sh (reported line 89)May include surrounding context.

sh
sudo dnf install -y nodejs npm
      elif have pacman; then
        info "installing node via pacman (may prompt for sudo password)..."
        sudo pacman -S --noconfirm nodejs npm
      else
        action "Node.js missing and no apt/dnf/pacman found. Install Node.js >= 18 via nvm: https://github.com/nvm-sh/nvm — then re-run this script."
        return 1

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/install.sh (reported line 193)May include surrounding context.

sh
echo "-- Codex --"
if [ -f "$HOME/.codex/auth.json" ]; then
  ok "~/.codex/auth.json present"
  if [ -f "$HOME/.codex/config.toml" ]; then
    ok "~/.codex/config.toml present"
  else
    action "~/.codex/config.toml missing — create it with requires_openai_auth / wire_api / base_url per references/panelists.md."

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/install.sh (reported line 194)May include surrounding context.

sh
if [ -f "$HOME/.codex/auth.json" ]; then
  ok "~/.codex/auth.json present"
  if [ -f "$HOME/.codex/config.toml" ]; then
    ok "~/.codex/config.toml present"
  else
    action "~/.codex/config.toml missing — create it with requires_openai_auth / wire_api / base_url per references/panelists.md."
  fi

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/install.sh (reported line 196)May include surrounding context.

sh
if [ -f "$HOME/.codex/auth.json" ]; then
  ok "~/.codex/auth.json present"
  if [ -f "$HOME/.codex/config.toml" ]; then
    ok "~/.codex/config.toml present"
  else
    action "~/.codex/config.toml missing — create it with requires_openai_auth / wire_api / base_url per references/panelists.md."
  fi

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/install.sh (reported line 199)May include surrounding context.

sh
if [ -f "$HOME/.codex/auth.json" ]; then
  ok "~/.codex/auth.json present"
  if [ -f "$HOME/.codex/config.toml" ]; then
    ok "~/.codex/config.toml present"
  else
    action "~/.codex/config.toml missing — create it with requires_openai_auth / wire_api / base_url per references/panelists.md."
  fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 102)May include surrounding context.

md
## Lessons from the Field

- **R1 Alignment = High-Confidence Signal**: When all five independently pick the same direction, it graduates directly to consensus without further debate.
- **Audit-Agent Value Density**: The most rigorous agent's (e.g., Claude) objections should directly rewrite final numbers, not just serve as QC.
- **Cost Expectation**: A full Conclave session (~30–50 CLI calls, 1.5–3 wall-clock hours). Use Codex medium/low effort for speed; parallelize all agents via `terminal(background=true)`.

---

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The skill creates persistent debate directories and stores briefs, mappings, constraints, and logs under ~/.hermes/debates. This is a real privacy concern because it retains potentially sensitive user input and agent outputs indefinitely in a predictable location that may later be copied or exposed.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
1. **Initialize the arena**: run `bash ~/.hermes/skills/conclave/scripts/init_debate.sh <topic-slug>`
   - Auto-creates `~/.hermes/debates/conclave-YYYYMMDD-<slug>/`
   - Generates the full directory structure + starter template files (brief.md / mapping.md / constraints.md / index.md)
2. **Fill the brief**: write brief.md, mapping.md, and constraints.md under `01_brief/`.
3. **Version & parameter check**: see `references/panelists.md` (commands, parameters, auth pitfalls for each agent).
4. **Pre-flight (update + ignition)**: run `bash ~/.hermes/skills/conclave/scripts/preflight.sh <arena-path>`
   - Phase A: best-effort self-update of all panelist CLIs (failures are non-fatal and logged; `--skip-update` bypasses).

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The workflow appends user clarification answers and constraints into persistent brief files, potentially storing sensitive facts revealed during the session. In context, this becomes more dangerous because the same archives are later retained indefinitely and exported into the working directory, multiplying exposure surfaces.

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

md
After receiving the topic and before writing the brief, the chair self-audits: is the topic ambiguous? Is any key constraint missing from the background?
- Any unclear point / multiple reasonable interpretations → **ask the user first; no debate until answered**.
- Questions must be multiple-choice (clarify tool, 2-4 options + Other); never make the user do essay questions; ask at most 4 critical ones at a time.
- After the user answers, write brief.md; the user's answers go into the brief's "Constraints" section as shared premises for all agents.
- If a trajectory-altering question arises mid-debate (e.g., a divergence hinges on a fact only the user knows) → the chair may pause, ask the user via clarify, append the answer to the brief, and resume.
- Do not force questions when there are none — if the topic is already clear, debate immediately; do not ritualize clarification.

Static analysis

No suspicious patterns detected.