Back to skill

Security audit

Open Dynamic Workflows

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent workflow purpose, but it asks users to install and run a mutable external daemon with model credentials and local workspace authority.

Review this before installing. Use a pinned, reviewed ODW commit or release, install in a restricted environment, avoid exposing provider API keys during dependency installation, and run the daemon only for repositories where you are comfortable granting multi-agent workflow authority. Watch for plan.json overwrites in the working directory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:32
Finding

Unpinned External Code Installation and Execution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/daemon-bridge.js:61
Finding

Unconditional Overwrite of Predictable plan.json Path

Content
View full analysis
"` from that directory. 3. The daemon returns a plan. 4. `fs.writeFileSync` truncates and replaces the existing `plan.json` without warning or approval. 5. The previous contents are lost. #### Symbolic-link redirection 1. An attacker with the ability to prepare or modify the working directory creates `plan.json` as a symbolic link to another file writable by the victim. 2. The victim runs the bridge's `plan` command in that directory. 3. The bridge follows the symbolic link and writes serialized plan data to the linked destination. 4. The desti ...[truncated 752 chars]
Remediation
View remediation
`, rather than always using `plan.json`. - Treat file creation as a mutating operation and obtain explicit user approval before writing. - Refuse to overwrite an existing destination unless the user supplies a deliberate `--force` option. - Open new files using exclusive creation semantics, such as the Node.js `wx` flag, to prevent silent replacement. - Reject symbolic-link destinations by using `lstat` checks and platform-appropriate no-follow protections. - When replacement is authorized, write to a securely created temporary file in the same directory and atomically rename it. - Apply restrictive file permissions where plan contents may contain sensitive project information. - Update `SKILL.md` to clearly disclose that the planning command creates a file in the current working directory. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
node scripts/daemon-bridge.js --check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
node scripts/daemon-bridge.js --check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
node scripts/daemon-bridge.js --check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
node scripts/daemon-bridge.js --check

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
node scripts/daemon-bridge.js --check

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises operational capabilities that involve environment secrets and network-dependent setup/execution, but it does not declare an explicit tool scope such as permissions or allowed-tools. That mismatch weakens policy enforcement and informed consent, because an agent may invoke code paths that access sensitive environment data or external resources without a clearly bounded capability contract.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
## Safety

- Read-only tools are auto-approved; file writes, shell, and git are approval-gated by ODW's config — never mutate without authorization.
- Model provider keys live in the environment / `~/.odw/config.json`, never in prompts or source.
- Respect the per-workflow token/cost budget.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code writes a new file to the current working directory with fs.writeFileSync, but there is no confirmation prompt before writing and no user-facing warning in the command usage or surrounding comments that running the plan command will create or overwrite plan.json. For this file, that file write is safety-relevant because it changes user workspace state silently.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.potential_exfiltration

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
scripts/daemon-bridge.js:24