Back to skill

Security audit

Coding Agent Runner

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a runbook for coding agents, but it normalizes unsandboxed autonomous execution, automatic commits/pushes, mutable installs, and fixed third-party PR attribution.

Review this skill carefully before installing. Use sandboxed/manual-approval modes by default, avoid --yolo except in an isolated disposable environment, inspect dependency installs before running them, and remove or override the fixed PR attribution before publishing anything under your account.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:213
Finding

Mandatory Third-Party Branding in Externally Published Pull Requests

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:44
Finding

Unsandboxed Autonomous Agent Execution with Approval Bypass

Content
View full analysis
. Commit and push.'" Enter tmux -S "$SOCKET" send-keys -t fix-99 "cd /tmp/issue-99 && pnpm install && codex --yolo 'Fix issue #99: . Commit and push.'" Enter ``` ### Technical Analysis The documented workflow explicitly recommends `--yolo`, which is identified in the skill itself as an alias for `--dangerously-bypass-approvals-and-sandbox`. This removes two primary security boundaries: - The sandbox that limits filesystem, process, and network access. - Human approval gates that prevent unexpected or destructive operations. The worktree examples combine this mode with dependency installation and instructions to commit and push. An autonomous agent operating in this configuration can execute repository-controlled commands with the invoking user's effective permissions and can publish changes using available Git credentials. Repository files, issue descriptions, dependency scripts, or other untrusted contextual input may influence the agent. Without sandboxing and approval gates, malicious instructions in those inputs can result in arbitrary local command execution or unauthorized remote repository actions. ### Attack Path ...[truncated 1507 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:125
Finding

Unpinned Global and Project Dependency Installation

Content
View full analysis
. Commit and push.'" Enter tmux -S "$SOCKET" send-keys -t fix-99 "cd /tmp/issue-99 && pnpm install && codex --yolo 'Fix issue #99: . Commit and push.'" Enter ``` ### Technical Analysis The global installation command does not pin an exact package version or integrity value. Its effective content can therefore change after the skill has been reviewed. A compromised publisher account, malicious release, or registry compromise could cause future users to install different code under the same command. The worktree workflow also invokes `pnpm install` without explicitly requiring a frozen lockfile, integrity verification, or lifecycle-script restrictions. Package managers may execute dependency lifecycle scripts during installation. In a cloned or untrusted repository, malicious package metadata or dependency changes could therefore trigger local code execution before Codex starts. The risk is amplified by immediately launching Codex with sandbox and approval protections disabled, although the unsafe dependency installation is independently a supply-chain concern. ### Attack Path 1. An attacker compromises the referenced package, one of its transitive dependencies, a package publisher, or relevant repository dependency metadata. 2. The user follows the skill and runs the unpinned global `npm install` command or executes `pnpm install` in the repository. 3. The package manager resolves mutable dependency content from the registry. 4. Malicious package files or lifecycle scripts execute with the ...[truncated 993 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

Codex CLI

Model: gpt-5.2-codex is the default (set in ~/.codex/config.toml)

Building/Creating (use --full-auto or --yolo)

bash

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

8. Cleanup

tmux -S "$SOCKET" kill-server git worktree remove /tmp/issue-78 git worktree remove /tmp/issue-99

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

8. Cleanup

tmux -S "$SOCKET" kill-server git worktree remove /tmp/issue-78 git worktree remove /tmp/issue-99

text

**Why worktrees?** Each Codex works in isolated branch, no conflicts. Can run 5+ parallel fixes!

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

The Pattern: workdir + background

bash
# Create temp space for chats/scratch work
SCRATCH=$(mktemp -d)

# Start agent in target directory ("little box" - only sees relevant files)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs operators to use dangerous execution modes such as --full-auto and --yolo, including a mode that bypasses approvals and sandboxing. Although one line notes that --yolo is dangerous, the guidance still normalizes risky autonomous execution for general building tasks without requiring explicit user confirmation, scope restriction, or safer defaults at the point of use.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

--full-auto allows the agent to auto-approve changes in the workspace, reducing human review over code and command execution. Even if sandboxed, normalizing autonomous write behavior for build tasks can still lead to unintended modifications, dependency changes, or unsafe generated code being accepted without review.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

Building/Creating (use --full-auto or --yolo)

bash
# --full-auto: sandboxed but auto-approves in workspace
bash workdir:~/project background:true command:"codex exec --full-auto \"Build a snake game with dark theme\""

# --yolo: NO sandbox, NO approvals (fastest, most dangerous)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
97% confidence
Finding

The --yolo example authorizes operation with no sandbox and no approvals, enabling the coding agent to make arbitrary filesystem or command changes autonomously. In a skill that is meant to be reused operationally, this materially increases the chance of destructive changes, secret exposure, or unintended command execution in the target repo or environment.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
# --full-auto: sandboxed but auto-approves in workspace
bash workdir:~/project background:true command:"codex exec --full-auto \"Build a snake game with dark theme\""

# --yolo: NO sandbox, NO approvals (fastest, most dangerous)
bash workdir:~/project background:true command:"codex --yolo \"Build a snake game with dark theme\""

# Note: --yolo is a shortcut for --dangerously-bypass-approvals-and-sandbox

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The rules section reinforces --full-auto for building as normative behavior, which institutionalizes autonomous approval rather than presenting it as an exceptional mode. This increases operational risk because consumers of the skill may follow the rule without understanding the trust boundary or validating generated changes.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

md
1. **Respect tool choice** — if user asks for Codex, use Codex. NEVER offer to build it yourself!
2. **Be patient** — don't kill sessions because they're "slow"
3. **Monitor with process:log** — check progress without interfering
4. **--full-auto for building** — auto-approves changes
5. **vanilla for reviewing** — no special flags needed
6. **Parallel is OK** — run many Codex processes at once for batch work
7. **NEVER start Codex in ~/clawd/** — it'll read your soul docs and get weird ideas about the org chart! Use the target project dir or /tmp for blank slate chats

Static analysis

No suspicious patterns detected.