📦
Audit History
mirrord-kafka - 1 audit
Audit version 1 Latest
Sep 29, 2026, 09:41 PM
Most alerts are false positives involving Markdown backticks, TLS property names, or read-only discovery. Four alerts identify credential exposure through command arguments or unencrypted key exports; unfiltered workload inspection adds a separate disclosure risk. No evidence found of malicious exfiltration or prompt injection.
6
Files scanned
1,165
Lines analyzed
7
Review items
0
False positives ignored
Confirmed security concerns (4)
High
Certificate/key files
openssl pkcs12 -in keystore.p12 -nocerts -nodes -out client-key.pem
The -nodes option exports an unencrypted private key to client-key.pem without specifying restrictive permissions. This creates an avoidable credential exposure risk.
High
Certificate/key files
openssl pkcs12 -in keystore.p12 -nocerts -nodes -out client-key.pem
The command uses -nodes to write an unencrypted private key without restrictive permission guidance. This unnecessarily exposes sensitive key material on disk.
High
Java keystore files
--from-literal=keystore.jks.base64="$(base64 < keystore.jks | tr -d '\n')" \
The private keystore is expanded into --from-literal, exposing credential-bearing bytes in process arguments. The same example also puts the store password in arguments.
Medium
Unfiltered Workload Inspection Can Expose Inline Secrets
The workflow requests complete deployment YAML to discover container names and environment variables. Inline passwords or tokens can enter agent context without filtering or redaction.
The command explicitly requests full YAML, including literal environment values. Exposure depends on workload contents, but no output filtering is specified.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Medium
Shell command substitution
--from-literal=keystore.jks.base64="$(base64 < keystore.jks | tr -d '\n')" \
The substitution puts the private keystore into kubectl command arguments through --from-literal. Process inspection or execution logging can capture this credential-bearing data.
Risk Factors
⚙️ External commands (50)
references/mirrord-property-list-crd.md:201 references/mirrord-property-list-crd.md:202 SKILL.md:20 SKILL.md:26 SKILL.md:28 SKILL.md:29 SKILL.md:31 SKILL.md:38 SKILL.md:41 SKILL.md:49 SKILL.md:50 SKILL.md:51 SKILL.md:52 SKILL.md:58-76 SKILL.md:76-78 SKILL.md:78-81 SKILL.md:81-84 SKILL.md:84-90 SKILL.md:90-96 SKILL.md:96-100 SKILL.md:100-108 SKILL.md:108-114 SKILL.md:114-119 SKILL.md:119-120 SKILL.md:120-121 SKILL.md:121 SKILL.md:122 SKILL.md:123-124 SKILL.md:124 SKILL.md:125-126 SKILL.md:126 SKILL.md:128-141 SKILL.md:141-143 SKILL.md:143 SKILL.md:149 SKILL.md:150 SKILL.md:151 SKILL.md:152 SKILL.md:153 SKILL.md:155-178 SKILL.md:178-180 SKILL.md:180 SKILL.md:182 SKILL.md:188-189 SKILL.md:189-202 SKILL.md:202-203 SKILL.md:203 SKILL.md:205-206 SKILL.md:206-219 SKILL.md:219-220
📁 Filesystem access (10)
Audited by: codex