Versioned security assessment

Report ID: SA-6D0B1144

10/5/2026, 6:28:34 PM

executor security assessment v1

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: codex Latest published report
Skill name
executor
Version
v1
Maintainer
atri10
Coverage
47 Files scanned · 12,235 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

High

5 confirmed security findings require attention.

Installation context

Check the current Skill page

This page summarizes report evidence only. The Skill page provides the canonical install advisory.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Reviewed all 400 presented findings; most are documentation, secret-hygiene checks, or scoped local tooling. Confirmed shell injection and identified unsafe rollback guidance, empty final-review ranges, untrusted prompt content, and plaintext remote authentication. No evidence found of intentional exfiltration; 1,468 omitted static matches still require manual review before publication. Static review was capped at 400/1868 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

Report position

Latest published report

Latest refers to the report sequence, not to artifact currentness.

Audit attestation

Active attestation

A public attestation is available for this exact report.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

47 Files scanned · 12,235 Lines analyzed

9 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Observed in 2 evidence locations

Network access

May connect to external services.

Observed in 8 evidence locations

Filesystem access

May read or write local files.

Observed in 49 evidence locations

Env variables

May read values from the process environment.

Observed in 17 evidence locations

External commands

May invoke commands or programs outside the Skill.

Observed in 52 evidence locations

Capability review items (4)
High
Process exec
try { cp.exec(process.env.BRAINSTORM_OPEN_CMD + ' ' + JSON.stringify(url), () => {}); } catch (e) {
The custom launcher passes a URL to a shell using JSON.stringify, which leaves shell substitutions active. A crafted URL hostname can execute commands.
High
Ruby/PHP system() call
stray=$(awk -F'|' '/^\|[ \t]*INIT-[0-9]+-P[0-9]+/ { c=$8; gsub(/[ `]/,"",c); gsub(/\/$/,"",c); if (c
An editable registry cell is concatenated into awk system() without shell quoting. Shell metacharacters in that cell can execute arbitrary local commands.
Low
Environment variable access (dot notation)
try { cp.exec(process.env.BRAINSTORM_OPEN_CMD + ' ' + JSON.stringify(url), () => {}); } catch (e) {
The custom launcher passes a URL to a shell using JSON.stringify, which leaves shell substitutions active. A crafted URL hostname can execute commands.
Low
Environment variable object
try { cp.exec(process.env.BRAINSTORM_OPEN_CMD + ' ' + JSON.stringify(url), () => {}); } catch (e) {
The custom launcher passes a URL to a shell using JSON.stringify, which leaves shell substitutions active. A crafted URL hostname can execute commands.

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (5)

RISK-001 High
Environment file access
try { cp.exec(process.env.BRAINSTORM_OPEN_CMD + ' ' + JSON.stringify(url), () => {}); } catch (e) {
The custom launcher passes a URL to a shell using JSON.stringify, which leaves shell substitutions active. A crafted URL hostname can execute commands.
RISK-002 High
Final Review Can Inspect an Empty Commit Range
Without an explicit base, final review defaults both revisions to the current HEAD. The required whole-branch review can therefore omit every implementation change.
The script never initializes plan_branch, so the normal fallback selects HEAD for both revisions. It then dispatches a final reviewer with that range.
RISK-003 High
Review Findings Enter Worker Instructions Without a Trust Boundary
Review findings are inserted verbatim into worker prompts. A manipulated verdict can supply behavioral instructions instead of evidence unless the worker preserves instruction hierarchy.
The dispatcher copies editable verdict prose into FINDINGS, and the renderer inserts replacement text unchanged. No evidence found of an embedded attack payload.
RISK-004 Medium
Recovery Guidance Can Discard Uncommitted User Work
Drift Recovery recommends "git checkout -- <paths>" for uncommitted edits without requiring approval or isolating agent-owned changes. Mixed user edits can be lost.
The recovery instruction explicitly recommends reverting paths without an ownership check. A broader destructive-action stop exists, but this recovery step omits it.
RISK-005 Medium
Remote Companion Authentication Uses Plaintext Transport
Non-loopback binding is supported, but companion HTTP and WebSocket URLs use plaintext transport. Direct remote access exposes session keys and screen data to interception.
The displayed session URL uses http and the browser connection uses ws. Loopback is the default, but direct remote binding has no transport encryption.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    Custom browser launching permits shell substitution in the URL.
    Replace cp.exec with execFile and explicit arguments. Validate URL hostnames and avoid treating JSON string escaping as shell escaping.
  2. FIX-002
    High
    Registry directory checks execute editable Markdown cells through a shell.
    Replace awk system() with directory checks that treat paths as data. Restrict registry paths to validated descendants of the execution store.
  3. FIX-003
    High
    The final-review default can compare HEAD against itself.
    Resolve the recorded plan fork revision and review its cumulative changes through HEAD. Reject equal revisions when implementation commits are expected.
  4. FIX-004
    High
    Editable review prose can become worker instructions.
    Mark inserted findings as untrusted evidence. Explicitly preserve higher-priority instructions and reject requests to bypass security checks or approvals.
  5. FIX-005
    Medium
    Static review capped
    Manually review the omitted 1468 static analyzer matches or reduce bundled generated/vendor/reference content before enabling automatic publication.
  6. FIX-006
    Medium
    Recovery instructions can revert mixed user and agent edits.
    Require explicit approval before destructive recovery. Preserve a patch and revert only verified agent-owned changes.
  7. FIX-007
    Medium
    Direct remote companion access transmits bearer authentication over plaintext.
    Keep loopback binding by default. Require an encrypted tunnel or TLS reverse proxy for remote use and support secure WebSocket URLs.
  8. FIX-008
    Medium
    The static catalog excludes 1,468 repeated or lower-priority matches.
    Complete manual review of the omitted matches before publication. Do not interpret this completed adjudication as clearance of unpresented findings.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
6d0b11444384184b7ae743742a7e233a9a705cd9
Content hash
63e48c41f96a799b94b43d2add903286ea55873005809372518febabbb1b7462
Tree hash
b345a44c247479ed9ce72e36705128657a5b1c9884959f109898b8dda223fb0f
Skill path
skills/atri10/executor
Audit payload hash
041e1d436d3f0dd3d4fcdb7f579eb720

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: active