Back to skill

Security audit

Agent Orchestrator

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent in-memory agent orchestrator package, but its resource-limit claims should not be relied on for production isolation without fixes.

Install only if you are comfortable with Chinese-only documentation and treating this as a prototype or library sample. Do not rely on its advertised CPU, memory, or concurrency limits for multi-tenant or production isolation until the scheduler/resource-manager enforcement and deepClone helper are hardened.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/scheduler.js:277
Finding

Task Scheduling Bypasses Configured Resource Limits

Content
View full analysis
= 0; i--) { const task = this.taskQueue[i]; // Find suitable agents let suitableAgents = availableAgents; if (task.requirements.capabilities) { suitableAgents = availableAgents.filter(agent => task.requirements.capabilities.every(cap => agent.capabilities.includes(cap) ) ); } if (suitableAgents.length === 0) continue; // Select agent using load balancer const selectedAgent = this.loadBalancer.select(suitableAgents); if (!selectedAgent) continue; // Assign task task.status = 'running'; task.assignedTo = selectedAgent.id; task.startedAt = Date.now(); // Remove from queue this.taskQueue.splice(i, 1); // Add to running this.runningTasks.set(task.id, task); // Set timeout this._setTaskTimeout(task); this.emit('task:assigned', task, selectedAgent.id); console.log(`[Scheduler] Task assigned: ${task.id} -> ${selectedAgent.id}`); // Update agent load selectedAgent.currentLoad++; } } ``` `src/resource-manager.js:70-107` defines validation that the scheduler never invokes: ```javascript canAllocateTask(agentId, resources = {}) { const agentRes = this.agentResources.get(agentId); if (!agentRes) return false; // Check concurrency if (agentR ...[truncated 3030 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
src/utils.js:26
Finding

Prototype Manipulation in deepClone Through __proto__

Content
View full analysis
deepClone(item)); } if (typeof obj === 'object') { const cloned = {}; for (const key in obj) { if (obj.hasOwnProperty(key)) { cloned[key] = deepClone(obj[key]); } } return cloned; } return obj; } ``` ### Technical Analysis The function copies attacker-controlled property names into a normal object using direct assignment: ```javascript cloned[key] = deepClone(obj[key]); ``` For an own property named `__proto__`, assignment to a normal object may invoke the legacy `Object.prototype.__proto__` setter instead of creating an ordinary data property. This changes the prototype of the cloned object to an attacker-controlled object. This is object-level prototype manipulation rather than automatic global modification of `Object.prototype`. Nevertheless, downstream code that trusts inherited properties may make incorrect authorization, configuration, or control-flow decisions. The utility is not used by the audited package's internal orchestration path, which limits immediate exposure. However, it can be imported directly from `src/utils.js` and may become exploitable when consumers use it to clone untrusted data. ### Attack Path 1. An application imports `deepClone()` directly from `src/utils.js`. 2. The application parses or constructs an untrusted object containing an own `__proto__` property. 3. The object is passed to `deepClone()`. 4. The assignment to `cloned["__proto__"]` changes the clone's prototype. 5. Downstream code reads a property without requiring it to be an own property. 6. An attacker-controlled inherited value ...[truncated 883 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The main description and the rest of the skill documentation are written in Chinese, with no indication that users can choose another language or that the skill is intentionally region-specific. This creates a natural-language policy concern because it effectively imposes a locale on users without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The comment at L218 and the implementation of setCustomSelector() at L219-L222 imply that custom selection strategies are supported. However, select() only dispatches among fixed built-in strategies at L98-L111 and has no 'custom' case, so setting a custom selector changes the strategy string without causing _custom() to be invoked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.