Back to skill

Security audit

CoralOS

Security checks for vulnerabilities and agentic risk

Overview

This instruction-only skill clearly describes a user-directed Coral Cloud workflow for launching and managing remote agent sessions, with no hidden local code or deceptive behavior found.

Install this only if you intend to operate Coral Cloud remote-agent sessions. Before creating a session, review the selected agent, payload, namespace, and expected permissions or costs, and treat any separately downloaded helper scripts or templates as unreviewed.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the user to create and launch a remote-agent session but does not warn that this action can trigger execution by external agents with real side effects, network activity, tool use, or cost. In a skill specifically designed to discover and run remote agents, omission of consent and risk guidance materially increases the chance of unsafe or unintended execution.

Static analysis

No suspicious patterns detected.