T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/ccg_orchestrator.sh:76- Finding
Model executors run without enforced filesystem or privilege boundaries
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent multi-model coding workflow, but it asks users to persist API keys and runs powerful model CLIs without technical containment.
Install only if you are comfortable giving the configured model CLIs the same local repository, environment-variable, and credential access as your user account. Prefer temporary or secret-manager based API keys, run it in a dedicated workspace or container, review dry-run output and diffs before execution, and do not include secrets in .claude artifacts or commits.
scripts/ccg_orchestrator.sh:76Model executors run without enforced filesystem or privilege boundaries
scripts/ccg_orchestrator.sh:49Repository cleanliness check does not detect untracked files
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- `scripts/ccg_orchestrator.sh --dry-run` 可快速排查参数;若脚本报 “缺少命令”,按 Quick Start 安装 CLI。
- 遇到模型超时:按 references/model-routing.md 的 fallback 重新分配,记录在 `.claude/log_*`。
- Claude/Codex/Gemini 均不得直接推送,必须由 Codex 在本地执行 `git commit`/`git push`。
- 禁止执行用户未授权的 destructive 命令(`git reset --hard`, `rm -rf` 等);若需求确实需要,必须在 OPSX 备注并得到显式同意。
- 任何自动生成的 patch 在合并前由人类或 Claude Review 二次比对。
## 附加参考
The skill explicitly tells users to export long-lived API keys in their shell profile so downstream scripts inherit them, but it gives no warning about persistence, accidental disclosure, or safer alternatives. Persisting secrets in shell startup files increases the chance of credential leakage through dotfile syncing, backups, shared accounts, terminal history, or later subprocess exposure.
该文件以中文编写并作为通用“模型路由指南”呈现,但没有说明这是特定区域/团队要求,也没有提供语言选择或用户 opt-in。根据规则,强制特定语言而无选择或正当限定,属于自然语言层面的语言/locale 政策问题。
The file title and all procedural instructions are written entirely in Chinese, which effectively imposes a language choice on users of the skill workflow. The document does not offer an alternative language, opt-in, or explain that the workflow is intentionally region- or team-specific.
This shell script includes its primary user instructions entirely in Chinese, and additional user-facing runtime messages throughout the file are also Chinese-only. That creates a language/locale policy issue because the skill enforces a specific language without any user opt-in or documented regional justification.
No suspicious patterns detected.