Versioned security assessment

Report ID: SA-BAD9DAFC

9/29/2026, 9:26:40 PM

mirrord-ci security assessment v1

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: codex Latest published report
Skill name
mirrord-ci
Version
v1.4
Maintainer
metalbear-co
Coverage
4 Files scanned · 4,165 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

High

4 confirmed security findings require attention.

Installation context

Check the current Skill page

This page summarizes report evidence only. The Skill page provides the canonical install advisory.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Of 400 supplied alerts, 399 concern documentation or intended CI operations; signature removal presents a genuine integrity risk. Four semantic findings cover certificate bypass, privileged containers, cluster-wide network changes, and unsupported isolation assurances. No evidence found of prompt injection or covert exfiltration; two omitted static matches still require manual review. Static review was capped at 400/402 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

Report position

Latest published report

Latest refers to the report sequence, not to artifact currentness.

Audit attestation

Active attestation

A public attestation is available for this exact report.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

4 Files scanned · 4,165 Lines analyzed

5 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 43 evidence locations

Filesystem access

May read or write local files.

Observed in 21 evidence locations

Env variables

May read values from the process environment.

Observed in 11 evidence locations

External commands

May invoke commands or programs outside the Skill.

Observed in 51 evidence locations

Capability review items (1)
High
sudo privilege escalation
`sudo codesign --remove-signature ./<your-binary>`
The command uses sudo to remove a copied binary's signature for SIP troubleshooting. This weakens binary integrity protections despite its legitimate compatibility purpose.

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (4)

RISK-001 High
Troubleshooting Recommends Disabling Certificate Validation
The guidance recommends "trust_any_certificate": true for certificate errors and states that every certificate becomes trusted. This can expose application connections to server impersonation and interception.
The troubleshooting example explicitly enables universal certificate trust without limiting it to an isolated diagnostic session or requiring restoration.
RISK-002 High
Permission Troubleshooting Broadens Container Privileges
The instructions recommend "privileged": true for permission or DNS failures. Privileged agents weaken container isolation and can expose the host when compromised.
The advice directly enables privileged execution without requiring administrator approval or evaluating narrower permissions. Actual exposure depends on deployment policy.
RISK-003 Medium
CI Troubleshooting Changes Cluster-Wide Networking
The Cilium workaround upgrades the release in kube-system and restarts its DaemonSet. Applying it without administrator review can disrupt networking for unrelated workloads.
The commands directly change cluster networking infrastructure, but the surrounding instructions provide no change approval, maintenance window, or rollback requirement.
RISK-004 Medium
Isolation Assurance Omits Shared Dependency Side Effects
The skill promises isolated execution without workload interference, but its examples connect directly to shared services without configuring database or traffic isolation. Tests can therefore modify shared data or trigger downstream effects.
The unconditional assurance exceeds the protections configured in the examples. The schema documents outbound traffic tunneling, which does not itself isolate dependency writes.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    Troubleshooting removes binary signatures with sudo.
    Prefer compatible development binaries. Require explicit approval for signature changes, restrict changes to disposable copies, and avoid sudo when ownership permits.
  2. FIX-002
    High
    Certificate errors are addressed by trusting every certificate.
    Configure the correct certificate chain and trust roots. Restrict any temporary bypass to isolated diagnostics with explicit approval and immediate restoration.
  3. FIX-003
    High
    Permission failures trigger privileged container recommendations.
    Diagnose RBAC, filesystem permissions, and security policies first. Require cluster administrator approval and document narrower capabilities before enabling privileged agents.
  4. FIX-004
    Medium
    Static review capped
    Manually review the omitted 2 static analyzer matches or reduce bundled generated/vendor/reference content before enabling automatic publication.
  5. FIX-005
    Medium
    The Cilium workaround changes shared networking infrastructure.
    Require administrator approval, a tested maintenance plan, and rollback steps. Pin the chart version and test changes outside shared clusters.
  6. FIX-006
    Medium
    Isolation claims omit potential shared dependency writes.
    Qualify the isolation claim. Add explicit traffic filters, isolated test data, database branches where supported, and approval before accessing shared services.
  7. FIX-007
    Low
    The supplied static catalog excludes two lower-priority or repeated matches.
    Provide the two omitted matches for manual adjudication before automatic publication.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2
Content hash
73bc8a4f38bfe2f15b5e34ff9f2db653101add3e0349c29f3116725555e247bf
Tree hash
a848c7cf96b3dd6f461a7b01a4fcda1d38d667e7139c6c7be42b866fc699014d
Skill path
skills/metalbear-co/mirrord-ci
Audit payload hash
7d75381d6f122d0ef2199faece974919

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: active