Back to skill

Security audit

Workspace Explorer

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to share a workspace remotely, but it asks users to run unreviewed remote code and expose the workspace through a public tunnel with limited safeguards.

Install only if you are comfortable giving remote IDE access to the chosen workspace and trusting the current GitHub repository and downloaded binaries at run time. Avoid sensitive repositories or directories with credentials, terminate sessions promptly, and prefer a version that bundles reviewed code, pins exact dependency versions, and verifies checksums or signatures.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:16
Finding

Execution of Mutable Remote Code and Unverified Downloaded Binaries

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:16-18, SKILL.md:23-27, HEARTBEAT.md:5-8, and HEARTBEAT.md:15-18
Vulnerability Type: Remote payload retrieval and insecure software supply chain
Risk Level: High

Evidence

SKILL.md:16-18 instructs the user or agent to clone a mutable repository without pinning a commit or verifying its integrity:

bash
## Installation

```bash
git clone https://github.com/mrbeandev/workspace-explorer.git
text

`SKILL.md:23-27` then instructs execution of a script obtained from that repository. The documentation states that the script downloads additional binaries:

```bash
Run the start script with the workspace path:

```bash
python3 {baseDir}/scripts/start_workspace.py /path/to/workspace

The script will:

  1. Download binaries on first run (code-server + cloudflared)
text

`HEARTBEAT.md:5-8` requests periodic execution of the same externally obtained script:

```markdown
## Checklist

1.  **Check Status**: Run `python3 {baseDir}/scripts/start_workspace.py --status`.
2.  **Monitor Activity**: If a workspace is active:

HEARTBEAT.md:15-18 repeats that command:

bash
## Commands

```bash
# Check if services are running
python3 {baseDir}/scripts/start_workspace.py --status
text

### Technical Analysis

The audited package contains only `SKILL.md` and `HEARTBEAT.md`; the referenced `scripts/start_workspace.py` implementation is not included. Instead, installation points to the current state of a personal GitHub repository with no immutable commit hash, signed release, checksum, or other integrity constraint.

Consequently, the code that is eventually executed can differ from the content available when this skill package was reviewed. If the repository, its maintainer account, release infrastructure, or referenced download locations are compromised, an attacker can alter `start_workspace.py` or the binaries it retrie
...[truncated 2919 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include the complete scripts/start_workspace.py implementation and supporting code in the reviewed skill package rather than requiring a mutable repository clone.
  2. If remote retrieval is unavoidable, pin the repository to a full immutable commit hash and verify that hash before execution. Prefer signed, versioned releases from a controlled organization.
  3. Pin exact versions of code-server and cloudflared. Publish expected SHA-256 or stronger hashes and verify each artifact before making it executable.
  4. Verify vendor signatures where available and fail closed if signature or checksum validation fails.
  5. Restrict downloads to HTTPS URLs on explicitly approved vendor domains. Do not follow unexpected redirects or select artifacts from untrusted mirrors.
  6. Vendor minimal required dependencies where licensing permits, and generate a software bill of materials documenting every downloaded component and version.
  7. Review status behavior and ensure --status performs no installation, downloading, tunnel creation, or other state-changing activity. Consider implementing status checking through a small bundled, read-only utility.
  8. Run the workspace service as a dedicated unprivileged account with access only to the explicitly selected workspace. Deny access to SSH keys, cloud credentials, unrelated home-directory files, and sensitive environment variables.
  9. Bind code-server only to localhost, require strong authentication, limit tunnel lifetime, and display an explicit confirmation before creating any public tunnel.
  10. Document all outbound connections, downloaded artifact sources, storage paths, and cleanup behavior so reviewers can verify the complete trust chain.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly creates a public Cloudflare URL to a live code-server instance serving the user's workspace, but the skill text does not prominently warn that this exposes the workspace over the public internet to anyone who obtains the URL and password. Because the workflow encourages sharing access and even installing extensions, users may underestimate the sensitivity of the exposure, increasing the risk of unintended data disclosure or remote misuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.