Skills mirrord-ci Audit History
📦

Audit History

mirrord-ci - 1 audit

Sep 29, 2026, 09:26 PM

Of 400 supplied alerts, 399 concern documentation or intended CI operations; signature removal presents a genuine integrity risk. Four semantic findings cover certificate bypass, privileged containers, cluster-wide network changes, and unsupported isolation assurances. No evidence found of prompt injection or covert exfiltration; two omitted static matches still require manual review. Static review was capped at 400/402 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

4
Files scanned
4,165
Lines analyzed
9
Review items
0
False positives ignored

Confirmed security concerns (4)

High
Troubleshooting Recommends Disabling Certificate Validation
The guidance recommends "trust_any_certificate": true for certificate errors and states that every certificate becomes trusted. This can expose application connections to server impersonation and interception.
The troubleshooting example explicitly enables universal certificate trust without limiting it to an isolated diagnostic session or requiring restoration.
High
Permission Troubleshooting Broadens Container Privileges
The instructions recommend "privileged": true for permission or DNS failures. Privileged agents weaken container isolation and can expose the host when compromised.
The advice directly enables privileged execution without requiring administrator approval or evaluating narrower permissions. Actual exposure depends on deployment policy.
Medium
CI Troubleshooting Changes Cluster-Wide Networking
The Cilium workaround upgrades the release in kube-system and restarts its DaemonSet. Applying it without administrator review can disrupt networking for unrelated workloads.
The commands directly change cluster networking infrastructure, but the surrounding instructions provide no change approval, maintenance window, or rollback requirement.
Medium
Isolation Assurance Omits Shared Dependency Side Effects
The skill promises isolated execution without workload interference, but its examples connect directly to shared services without configuring database or traffic isolation. Tests can therefore modify shared data or trigger downstream effects.
The unconditional assurance exceeds the protections configured in the examples. The schema documents outbound traffic tunneling, which does not itself isolate dependency writes.
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
sudo privilege escalation
`sudo codesign --remove-signature ./<your-binary>`
The command uses sudo to remove a copied binary's signature for SIP troubleshooting. This weakens binary integrity protections despite its legitimate compatibility purpose.

Risk Factors

⚙️ External commands (50)
🌐 Network access (47)
📁 Filesystem access (30)
🔑 Env variables (11)
Audited by: codex