Versioned security assessment

Report ID: SA-BAD9DAFC

9/28/2026, 4:21:58 PM

agent-fs security assessment v1

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: codex Latest published report
Skill name
agent-fs
Version
v1
Maintainer
desplega-ai
Coverage
1 Files scanned · 495 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

Medium

1 confirmed security finding requires attention.

Installation context

Check the current Skill page

This page summarizes report evidence only. The Skill page provides the canonical install advisory.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Most static findings are Markdown delimiters, documented application operations, or scoped authentication examples rather than malicious behavior. Six findings identify risky FUSE permission changes and forced system configuration replacement; one additional finding covers S3 credentials exposed through command arguments. No evidence found of prompt injection or intentional credential exfiltration; external CLI implementations were not included in this review.

Report position

Latest published report

Latest refers to the report sequence, not to artifact currentness.

Audit attestation

Active attestation

A public attestation is available for this exact report.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

1 Files scanned · 495 Lines analyzed

7 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 5 evidence locations

Filesystem access

May read or write local files.

Observed in 8 evidence locations

Env variables

May read values from the process environment.

Observed in 4 evidence locations

External commands

May invoke commands or programs outside the Skill.

Observed in 53 evidence locations

Capability review items (6)
High
sudo privilege escalation
sudo chmod 666 /dev/fuse
The unconditional chmod 666 grants every local user device read and write access. It can weaken existing restrictions without checking sandbox isolation.
High
sudo privilege escalation
sudo ln -sf /proc/mounts /etc/mtab
The command force-replaces /etc/mtab as root without inspecting its current state. This can disrupt existing mount-table configuration on systems requiring a different setup.
High
sudo privilege escalation
echo user_allow_other | sudo tee -a /etc/fuse.conf
Appending user_allow_other globally enables unprivileged users to request cross-user FUSE access. The shown mount does not need this policy relaxation.
High
Linux /proc filesystem access
sudo ln -sf /proc/mounts /etc/mtab
The risk is force-replacing /etc/mtab as root with a /proc/mounts link, not reading process secrets. No existing-configuration check protects this system change.
High
Non-standard device file access
sudo chmod 666 /dev/fuse
The device operation makes /dev/fuse writable by all local users. Unconditional permission broadening can defeat a deployment's existing device-access restrictions.
High
Symlink creation
sudo ln -sf /proc/mounts /etc/mtab
The root-level ln -sf can replace an existing /etc/mtab entry without checking whether replacement is appropriate. This risks disrupting host mount-table configuration.

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (1)

RISK-001 Medium
S3 Onboarding Exposes Credentials Through Command Arguments
The onboarding example passes credentials through --s3-access-key and --s3-secret-key without a handling warning. Following it can expose keys in process arguments, shell history, or recorded agent commands.
The example explicitly places both credentials in command arguments. Unlike the remote-mount guidance, this workflow gives no warning about argument-based credential exposure.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    The sandbox example grants every local user read and write access to the FUSE device.
    Check existing device permissions first and use narrowly scoped group or device access instead of unconditional chmod 666.
  2. FIX-002
    High
    The setup force-replaces /etc/mtab without checking the existing system configuration.
    Inspect the existing mount-table configuration and modify it only when required, with explicit administrator approval and a recovery plan.
  3. FIX-003
    High
    The example enables user_allow_other globally even though its mount command does not request shared access.
    Omit this setting by default and require explicit approval when sharing mounts with other local users is necessary.
  4. FIX-004
    Medium
    Custom S3 onboarding passes access credentials through command-line arguments.
    Provide a supported protected credential input and warn against exposing keys through process listings, shell history, or agent transcripts.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2
Content hash
2c3aba474d7fbbdf6062bb245e12e49512c1da615bf3cef8595a445b0c9a4c15
Tree hash
2bc7c7e738cad56c631e55919cee7592900b8e267967c05e449568677d212b4d
Skill path
skills/desplega-ai/agent-fs
Audit payload hash
95fd96c48262b89f8ef7389a25980cc8

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: active