Back to skill

Security audit

GoLive

Security checks for vulnerabilities and agentic risk

Overview

This is a deployment skill that uses local credentials and cloud APIs in expected, disclosed ways, with explicit approval gates for production, DNS, and deletion.

Install only if you want this agent to help deploy to your own cloud accounts. Use scoped, expiring provider tokens where possible, review every generated plan carefully, and do not approve production, DNS, live-payment, or deletion flags unless the named destination and changes are exactly what you intend.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (63)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 233)May include surrounding context.

md
For Supabase, distinguish token **capabilities** from **resource scope**: "Full access" to one
project cannot create another project or manage its organization. A `/profile` 403 can mean a
project-scoped token, not an invalid key. Explain the required scope; don't blindly ask for another
Full access token. A passing account check doesn't prove every later endpoint permission.

### 4. Plan: `plan --json`
Explain the steps by provider, in plain language, and call out:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8178)May include surrounding context.

js
For Supabase, distinguish token **capabilities** from **resource scope**: "Full access" to one
project cannot create another project or manage its organization. A `/profile` 403 can mean a
project-scoped token, not an invalid key. Explain the required scope; don't blindly ask for another
Full access token. A passing account check doesn't prove every later endpoint permission.

### 4. Plan: `plan --json`
Explain the steps by provider, in plain language, and call out:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 13692)May include surrounding context.

js
For Supabase, distinguish token **capabilities** from **resource scope**: "Full access" to one
project cannot create another project or manage its organization. A `/profile` 403 can mean a
project-scoped token, not an invalid key. Explain the required scope; don't blindly ask for another
Full access token. A passing account check doesn't prove every later endpoint permission.

### 4. Plan: `plan --json`
Explain the steps by provider, in plain language, and call out:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 16379)May include surrounding context.

js
For Supabase, distinguish token **capabilities** from **resource scope**: "Full access" to one
project cannot create another project or manage its organization. A `/profile` 403 can mean a
project-scoped token, not an invalid key. Explain the required scope; don't blindly ask for another
Full access token. A passing account check doesn't prove every later endpoint permission.

### 4. Plan: `plan --json`
Explain the steps by provider, in plain language, and call out:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 19182)May include surrounding context.

js
For Supabase, distinguish token **capabilities** from **resource scope**: "Full access" to one
project cannot create another project or manage its organization. A `/profile` 403 can mean a
project-scoped token, not an invalid key. Explain the required scope; don't blindly ask for another
Full access token. A passing account check doesn't prove every later endpoint permission.

### 4. Plan: `plan --json`
Explain the steps by provider, in plain language, and call out:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/godaddy.md (reported line 5)May include surrounding context.

md
Automated DNS-record adapter with two transports — same endpoints and safety rules either way: the
official GoDaddy CLI (`gddy`, the default when installed and logged in) and a scoped REST Personal
Access Token (the fallback). The Vercel-attached custom-domain journey passed disposable live runs
on both transports: the CLI path created both records through `gddy api call` with the user's OAuth
session, and the v3 update-by-ID (PUT) endpoint was separately validated through that same session.
golive's owned-record update flows (SPF merge, singleton replace, TTL drift) and the REST

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/godaddy.md (reported line 25)May include surrounding context.

md
Automated DNS-record adapter with two transports — same endpoints and safety rules either way: the
official GoDaddy CLI (`gddy`, the default when installed and logged in) and a scoped REST Personal
Access Token (the fallback). The Vercel-attached custom-domain journey passed disposable live runs
on both transports: the CLI path created both records through `gddy api call` with the user's OAuth
session, and the v3 update-by-ID (PUT) endpoint was separately validated through that same session.
golive's owned-record update flows (SPF merge, singleton replace, TTL drift) and the REST

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/updates.md (reported line 61)May include surrounding context.

md
Compatible state keeps resource IDs, fingerprints and evidence. Identical completed operations
remain completed. Changed, failed or ambiguous historical writes may require reconciliation;
do not delete state or force replays to get past that guard. Two exemptions resume by themselves,
because the step declares it: teardown's destruction steps (a deletion re-checks ownership and is
idempotent) and any step whose risk declares `risk.replayable` (an idempotent write that re-observes
the provider and golive's own recorded resource before acting, e.g. the auth test account's password

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/golive.mjs (reported line 13439)May include surrounding context.

js
Compatible state keeps resource IDs, fingerprints and evidence. Identical completed operations
remain completed. Changed, failed or ambiguous historical writes may require reconciliation;
do not delete state or force replays to get past that guard. Two exemptions resume by themselves,
because the step declares it: teardown's destruction steps (a deletion re-checks ownership and is
idempotent) and any step whose risk declares `risk.replayable` (an idempotent write that re-observes
the provider and golive's own recorded resource before acting, e.g. the auth test account's password

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
90% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · references/vercel.md (reported line 52)May include surrounding context.

md
golive deployed instead of "no platform" (issue #66). Keep `.vercel/` out of git; `.golive/state.json`
  remains golive's own record.
- **Keeps its own files out of the upload.** `vercel deploy` uploads this folder and serves what it
  uploaded, and its ignore filter reads **only** `.vercelignore`/`.nowignore` — never `.gitignore`.
  Before a deploy on an unframed app golive therefore plans `upload:excludes`: it appends a marked
  block to `.vercelignore` (created when absent, your rules above untouched) for `.golive/`,
  `golive.yaml`, `GOLIVE_REPORT.md`, `GOLIVE_HANDOVER.md`, `SHIP_REPORT.md` and `docs/GOLIVE-*`, and

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8000)May include surrounding context.

js
if (fd !== void 0) closeSync5(fd);
  }
}
function credential(value, keychain = false) {
  const captured = new Secret("supabase-cli-stored", value || "(empty)");
  let raw2 = captured.reveal().trim();
  if (keychain && raw2.startsWith("go-keyring-base64:")) {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8003)May include surrounding context.

js
if (fd !== void 0) closeSync5(fd);
  }
}
function credential(value, keychain = false) {
  const captured = new Secret("supabase-cli-stored", value || "(empty)");
  let raw2 = captured.reveal().trim();
  if (keychain && raw2.startsWith("go-keyring-base64:")) {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8040)May include surrounding context.

js
if (fd !== void 0) closeSync5(fd);
  }
}
function credential(value, keychain = false) {
  const captured = new Secret("supabase-cli-stored", value || "(empty)");
  let raw2 = captured.reveal().trim();
  if (keychain && raw2.startsWith("go-keyring-base64:")) {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8043)May include surrounding context.

js
if (fd !== void 0) closeSync5(fd);
  }
}
function credential(value, keychain = false) {
  const captured = new Secret("supabase-cli-stored", value || "(empty)");
  let raw2 = captured.reveal().trim();
  if (keychain && raw2.startsWith("go-keyring-base64:")) {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8053)May include surrounding context.

js
if (fd !== void 0) closeSync5(fd);
  }
}
function credential(value, keychain = false) {
  const captured = new Secret("supabase-cli-stored", value || "(empty)");
  let raw2 = captured.reveal().trim();
  if (keychain && raw2.startsWith("go-keyring-base64:")) {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8003)May include surrounding context.

js
function credential(value, keychain = false) {
  const captured = new Secret("supabase-cli-stored", value || "(empty)");
  let raw2 = captured.reveal().trim();
  if (keychain && raw2.startsWith("go-keyring-base64:")) {
    const encoded = raw2.slice("go-keyring-base64:".length);
    if (!/^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=)?$/.test(encoded)) throw failure("Supabase CLI stored credential is malformed.");
    raw2 = Buffer.from(encoded, "base64").toString("utf8");

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8004)May include surrounding context.

js
function credential(value, keychain = false) {
  const captured = new Secret("supabase-cli-stored", value || "(empty)");
  let raw2 = captured.reveal().trim();
  if (keychain && raw2.startsWith("go-keyring-base64:")) {
    const encoded = raw2.slice("go-keyring-base64:".length);
    if (!/^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=)?$/.test(encoded)) throw failure("Supabase CLI stored credential is malformed.");
    raw2 = Buffer.from(encoded, "base64").toString("utf8");

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8038)May include surrounding context.

js
function credential(value, keychain = false) {
  const captured = new Secret("supabase-cli-stored", value || "(empty)");
  let raw2 = captured.reveal().trim();
  if (keychain && raw2.startsWith("go-keyring-base64:")) {
    const encoded = raw2.slice("go-keyring-base64:".length);
    if (!/^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=)?$/.test(encoded)) throw failure("Supabase CLI stored credential is malformed.");
    raw2 = Buffer.from(encoded, "base64").toString("utf8");

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8029)May include surrounding context.

js
if (!isAbsolute3(root)) throw failure("SUPABASE_HOME must be an absolute path for safe credential reuse.");
  const profile = ctx.env("SUPABASE_PROFILE") || storedFile(join8(root, "profile"), false)?.trim() || "supabase";
  if (profile.toLowerCase() !== "supabase") throw failure("The selected Supabase CLI profile is not the supported production supabase profile; golive will not use another profile or API.");
  const noKeyring = ctx.env("SUPABASE_NO_KEYRING") === "1";
  const wsl = options.wsl ?? (platform2 === "linux" && (() => {
    try {
      return /WSL|Microsoft/.test(readFileSync7("/proc/sys/kernel/osrelease", "utf8"));

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8037)May include surrounding context.

js
if (!isAbsolute3(root)) throw failure("SUPABASE_HOME must be an absolute path for safe credential reuse.");
  const profile = ctx.env("SUPABASE_PROFILE") || storedFile(join8(root, "profile"), false)?.trim() || "supabase";
  if (profile.toLowerCase() !== "supabase") throw failure("The selected Supabase CLI profile is not the supported production supabase profile; golive will not use another profile or API.");
  const noKeyring = ctx.env("SUPABASE_NO_KEYRING") === "1";
  const wsl = options.wsl ?? (platform2 === "linux" && (() => {
    try {
      return /WSL|Microsoft/.test(readFileSync7("/proc/sys/kernel/osrelease", "utf8"));

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8029)May include surrounding context.

js
if (!isAbsolute3(root)) throw failure("SUPABASE_HOME must be an absolute path for safe credential reuse.");
  const profile = ctx.env("SUPABASE_PROFILE") || storedFile(join8(root, "profile"), false)?.trim() || "supabase";
  if (profile.toLowerCase() !== "supabase") throw failure("The selected Supabase CLI profile is not the supported production supabase profile; golive will not use another profile or API.");
  const noKeyring = ctx.env("SUPABASE_NO_KEYRING") === "1";
  const wsl = options.wsl ?? (platform2 === "linux" && (() => {
    try {
      return /WSL|Microsoft/.test(readFileSync7("/proc/sys/kernel/osrelease", "utf8"));

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8038)May include surrounding context.

js
if (!isAbsolute3(root)) throw failure("SUPABASE_HOME must be an absolute path for safe credential reuse.");
  const profile = ctx.env("SUPABASE_PROFILE") || storedFile(join8(root, "profile"), false)?.trim() || "supabase";
  if (profile.toLowerCase() !== "supabase") throw failure("The selected Supabase CLI profile is not the supported production supabase profile; golive will not use another profile or API.");
  const noKeyring = ctx.env("SUPABASE_NO_KEYRING") === "1";
  const wsl = options.wsl ?? (platform2 === "linux" && (() => {
    try {
      return /WSL|Microsoft/.test(readFileSync7("/proc/sys/kernel/osrelease", "utf8"));

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8040)May include surrounding context.

js
if (!noKeyring && !wsl) {
    if (platform2 !== "darwin") throw failure("This OS keyring cannot be safely reused by golive. On Linux, run `SUPABASE_NO_KEYRING=1 supabase login --profile supabase` and run golive with SUPABASE_NO_KEYRING=1 to use the CLI private file.");
    for (const account2 of ["supabase", "access-token"]) {
      let answer = await keychainRead(ctx, account2, KEYCHAIN_TIMEOUT_MS);
      if (answer.kind === "timeout") {
        ctx.log.warn(`macOS is asking whether golive may read the Supabase CLI Keychain item (read-only; golive never changes the Keychain). Click "Allow" in that dialog, or "Always Allow" to record the permission permanently for this item. Waiting ${KEYCHAIN_ATTENDED_TIMEOUT_MS / 1e3}s for the answer.`);
        answer = await keychainRead(ctx, account2, KEYCHAIN_ATTENDED_TIMEOUT_MS);

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8042)May include surrounding context.

js
if (!noKeyring && !wsl) {
    if (platform2 !== "darwin") throw failure("This OS keyring cannot be safely reused by golive. On Linux, run `SUPABASE_NO_KEYRING=1 supabase login --profile supabase` and run golive with SUPABASE_NO_KEYRING=1 to use the CLI private file.");
    for (const account2 of ["supabase", "access-token"]) {
      let answer = await keychainRead(ctx, account2, KEYCHAIN_TIMEOUT_MS);
      if (answer.kind === "timeout") {
        ctx.log.warn(`macOS is asking whether golive may read the Supabase CLI Keychain item (read-only; golive never changes the Keychain). Click "Allow" in that dialog, or "Always Allow" to record the permission permanently for this item. Waiting ${KEYCHAIN_ATTENDED_TIMEOUT_MS / 1e3}s for the answer.`);
        answer = await keychainRead(ctx, account2, KEYCHAIN_ATTENDED_TIMEOUT_MS);

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/golive.mjs (reported line 8043)May include surrounding context.

js
if (!noKeyring && !wsl) {
    if (platform2 !== "darwin") throw failure("This OS keyring cannot be safely reused by golive. On Linux, run `SUPABASE_NO_KEYRING=1 supabase login --profile supabase` and run golive with SUPABASE_NO_KEYRING=1 to use the CLI private file.");
    for (const account2 of ["supabase", "access-token"]) {
      let answer = await keychainRead(ctx, account2, KEYCHAIN_TIMEOUT_MS);
      if (answer.kind === "timeout") {
        ctx.log.warn(`macOS is asking whether golive may read the Supabase CLI Keychain item (read-only; golive never changes the Keychain). Click "Allow" in that dialog, or "Always Allow" to record the permission permanently for this item. Waiting ${KEYCHAIN_ATTENDED_TIMEOUT_MS / 1e3}s for the answer.`);
        answer = await keychainRead(ctx, account2, KEYCHAIN_ATTENDED_TIMEOUT_MS);

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/golive.mjs:10305

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/install-lib.mjs:187