Back to skill

Security audit

Ops Deck Lite

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a local productivity setup, but it asks users to persistently index broad local codebases without enough scoping, warning, or cleanup guidance.

Review before installing. Use this only for repositories where local indexing and summaries are acceptable, exclude secrets and sensitive directories, prefer a virtual environment and pinned dependencies, avoid the cron job unless you intentionally want ongoing re-indexing, and add a clear way to remove any PM2 and crontab changes.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Error
Location
SKILL.md:156
Finding

Persistent Nightly Re-indexing Through User Crontab

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 156-162
Vulnerability Type: Scheduled-task persistence
Risk Level: High

Complete Code Snippet:

bash
pm2 start ecosystem.config.cjs
pm2 save

# Initial code index (takes a few minutes depending on codebase size)
curl -X POST http://localhost:5204/api/index?summarize=true

# Set up nightly re-index
(crontab -l 2>/dev/null; echo "0 4 * * * curl -s -X POST http://localhost:5204/api/index?summarize=true > /dev/null") | crontab -

Technical Analysis

The setup command modifies the current user's crontab and installs a task that invokes the indexing endpoint every day at 04:00. The task survives the Skill setup session and continues operating until explicitly removed.

Although periodic re-indexing supports the advertised search functionality and is disclosed as a feature, it is not necessary for on-demand semantic search. The instruction therefore exceeds the minimum persistence required for the core functionality. It also lacks an explicit opt-in prompt, an uninstall command, an idempotency check, and a unique marker for safe management.

Running the setup repeatedly can append duplicate cron entries. In addition, the cron job trusts whichever process is listening on port 5204 in the future. If that local service is replaced, modified, or compromised, the persistent task will continue sending requests to it automatically. The use of pm2 save also preserves the PM2 process list for restoration where PM2 startup integration has already been configured, although this artifact does not itself execute pm2 startup.

Attack Path

  1. A user follows the documented setup instructions.
  2. The pipeline reads the existing user crontab, appends the supplied entry, and writes the resulting configuration back with crontab -.
  3. The scheduled entry remains active across terminal sessions and system restarts where cron is enabled.
  4. At 04:00 each ...[truncated 855 chars]
Remediation
View remediation

Remediation Suggestions

  • Make scheduled indexing explicitly opt-in and keep the default setup limited to on-demand indexing.
  • Present the exact schedule, expected resource usage, indexed path scope, and persistence effects before installation.
  • Add a uniquely marked and idempotent cron entry rather than blindly appending it.
  • Check for an existing entry before making changes to prevent duplicate jobs.
  • Supply a documented uninstall command that removes only the entry created by this Skill.
  • Consider using an application-level scheduler that is disabled by default and managed through the service configuration.
  • Add timeouts, locking, and overlap prevention so a new indexing run cannot start while an earlier run remains active.
  • Verify that the service is bound only to loopback and authenticate state-changing endpoints where practical.
  • Do not use pm2 save unless persistent process restoration is separately requested and explained to the user.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:86
Finding

Unpinned Global Packages and Model Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 86-91; duplicated in abbreviated form in README.md, lines 22-24
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Complete Code Snippet:

bash
npm install -g pm2
pip install fastapi uvicorn aiofiles

# Ollama embedding model
ollama pull qwen3-embedding:8b

The corresponding quick-start instructions in README.md are:

bash
ollama pull qwen3-embedding:8b
npm install -g pm2
pm2 start ecosystem.config.cjs
curl -X POST http://localhost:5204/api/index?summarize=true

Technical Analysis

The instructions install npm and Python packages without exact version constraints, lockfiles, or integrity verification. The Ollama model is likewise referenced by a mutable tag rather than a verified immutable digest. Consequently, the components installed at setup time may differ from those reviewed or tested by the Skill author.

Installing PM2 globally expands the affected scope beyond an isolated project environment and may require elevated permissions depending on the host configuration. Python packages are installed into whichever environment the invoking pip command currently targets, potentially changing a shared or system environment.

No evidence shows that the named packages are typosquatted or currently malicious. The risk arises from mutable dependency resolution and broad installation scope: a compromised upstream release, registry account, distribution channel, or model tag could cause future users to retrieve unreviewed content.

Attack Path

  1. A user runs the documented dependency installation commands.
  2. npm, pip, and Ollama resolve the current artifacts associated with the unpinned names or model tag.
  3. A later, compromised, or incompatible upstream artifact is downloaded without comparison to a reviewed lockfile, version, hash, or digest.
  4. Package installation hooks or subsequently la ...[truncated 769 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin exact npm and Python package versions that have been tested.
  • Provide lockfiles and verify package integrity through checksums or package-manager integrity metadata.
  • Pin the Ollama model to an immutable, verified digest where supported.
  • Install Python dependencies inside a dedicated virtual environment rather than an ambient or system environment.
  • Prefer a project-local PM2 dependency invoked through npx or a package script instead of global installation.
  • Document supported versions of Node.js, Python, Ollama, and all direct dependencies.
  • Use a controlled update process that reviews dependency changes before updating pins.
  • Avoid advising users to run package-manager commands with administrative privileges.
  • Include the actual service implementations and dependency manifests so users can review and reproduce the advertised deployment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (9)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

bash
# Search
curl -s -X POST http://localhost:5204/api/search \
  -H "Content-Type: application/json" \
  -d '{"query":"database connection pooling","mode":"hybrid","limit":10}'

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

The documented prompt library includes mutable and destructive endpoints, including DELETE and PUT, but the skill provides no mention of authentication, authorization, input validation, or scoping. In context, this makes the design more dangerous because prompts can influence downstream agent behavior, so unauthorized modification or deletion could become a prompt-supply-chain issue.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

- GET /api/prompts/:id (get one)

- POST /api/prompts (create)

- PUT /api/prompts/:id (update)

- DELETE /api/prompts/:id (delete)

- SQLite or JSON file storage

text

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

}, { name: 'prompt-library-api', cwd: './pipeline/work/prompt-library/backend', script: 'server.js', autorestart: true, }, ] };

text

### 5. Start and index

```bash
pm2 start ecosystem.config.cjs
pm2 save

# Initial code index (takes a few minutes depending on codebase size)
curl -X POST http://localhost:5204/api/index?summarize=true

# Set up nightly re-index
(crontab -l 2>/dev/null; echo "0 4 * * * curl -s -X POST http://localhost:5204/api/index?summarize=true > /dev/null") | crontab -

Agent Integration

Add to your AGENTS.md or TOOLS.md:

markdown
## Code Search API (USE THIS FIRST)

Before you grep, before you spawn a sub-agent, before you read 10 files: HIT THIS API.

curl -s -X POST http://localhost:5204/api/search \
  -H "Content-Type: application/json" \
  -d '{"query":"your search here","mode":"hybrid","limit":10}'

## Prompt Library

Before writing a prompt from scratch, check if one exists:

curl -s http://localhost:5202/api/pro

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to index and summarize an entire local codebase with embeddings and natural-language summaries, but it does not warn that this processing can expose sensitive source code, secrets, proprietary logic, or regulated data to local services and logs. Even though the stack is described as local-only, sensitive content is still transmitted to local APIs and persisted in SQLite indexes/summaries, which meaningfully increases confidentiality risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

bash
# Search
curl -s -X POST http://localhost:5204/api/search \
  -H "Content-Type: application/json" \
  -d '{"query":"database connection pooling","mode":"hybrid","limit":10}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
"

# Get a specific prompt
curl -s http://localhost:5202/api/prompts/<id>

# Create a prompt
curl -s -X POST http://localhost:5202/api/prompts \

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill instructs users to install a persistent cron job that will continue running after the session ends, modifying host state and repeatedly operating on local code without an explicit warning or consent checkpoint. Persistence is security-relevant because it creates ongoing automated behavior that can process newly added sensitive code and is easy for users to forget once installed.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

curl -X POST http://localhost:5204/api/index?summarize=true

Set up nightly re-index

(crontab -l 2>/dev/null; echo "0 4 * * * curl -s -X POST http://localhost:5204/api/index?summarize=true > /dev/null") | crontab -

text

## Agent Integration

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

md
Before you grep, before you spawn a sub-agent, before you read 10 files: HIT THIS API.

curl -s -X POST http://localhost:5204/api/search \
  -H "Content-Type: application/json" \
  -d '{"query":"your search here","mode":"hybrid","limit":10}'

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The documentation recommends a scheduled nightly re-index across user codebases without warning about its broad operational impact, including CPU usage, storage churn, accidental indexing of newly added sensitive files, and repeated summarization of confidential content. This is not overtly destructive, but it can have wide scope and surprise users in environments with multiple repositories or changing data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.