📦
Audit History
mirrord-operator - 1 audit
Audit version 1 Latest
Sep 29, 2026, 09:50 PM
Most alerts are false positives from Markdown formatting, YAML comments, and legitimate configuration references. Confirmed risks involve inline credentials, trial response exposure, and HTTP licensing; additional findings address transport security, database authentication, and excessive permissions. No evidence found of prompt injection or malicious intent; cluster changes and trial registration explicitly require user approval.
5
Files scanned
2,000
Lines analyzed
22
Review items
0
False positives ignored
Confirmed security concerns (14)
High
Certificate/key files
| `cloud.apiKey.key` | Inline value — plaintext in the pod spec. Dev/test only. |
This option places a real cloud API key in plaintext pod configuration when used. The development-only warning reduces exposure but does not prevent credential disclosure.
High
Certificate/key files
| `license.key` | Inline license key. Deprecated for cloud; still the shared secret for a self-hoste
The documented license.key option embeds a shared authentication secret in Helm values when followed. This can expose credentials through configuration storage or accidental commits despite safer alternatives.
High
Certificate/key files
| `license.file.secret.data.license.pem` | Inline PEM as a YAML literal block (air-gapped). |
The inline example places offline license material in Helm values, contrary to the skill's secret-handling boundary. Following it can expose licensing material through shared configuration.
High
Certificate/key files
- **Cloud API key (default):** the operator exchanges a cloud API key for a license over the API. Pr
This option places a real cloud API key in plaintext pod configuration when used. The development-only warning reduces exposure but does not prevent credential disclosure.
High
Certificate/key files
- **License key (deprecated for cloud):** `license.key` / `license.keyRef` (Secret data key `OPERATO
The documented license.key option embeds a shared authentication secret in Helm values when followed. This can expose credentials through configuration storage or accidental commits despite safer alternatives.
High
Certificate/key files
- **Air-gapped:** offline PEM (`license.file.secret.data.license.pem` or `license.pemRef`) or a `lic
The inline example places offline license material in Helm values, contrary to the skill's secret-handling boundary. Following it can expose licensing material through shared configuration.
High
Certificate/key files
- **Inline (dev/test only)** — `cloud.apiKey.key: <YOUR_API_KEY>` (lands in the pod spec as plaintex
This option places a real cloud API key in plaintext pod configuration when used. The development-only warning reduces exposure but does not prevent credential disclosure.
High
Certificate/key files
**B. License key (deprecated for cloud auth).** Still valid for existing installs and **required** w
The documented license.key option embeds a shared authentication secret in Helm values when followed. This can expose credentials through configuration storage or accidental commits despite safer alternatives.
High
Certificate/key files
license.pem: |
The inline example places offline license material in Helm values, contrary to the skill's secret-handling boundary. Following it can expose licensing material through shared configuration.
High
Certificate/key files
<contents of your license.pem>
The inline example places offline license material in Helm values, contrary to the skill's secret-handling boundary. Following it can expose licensing material through shared configuration.
High
IAM Database Branches Default to Trust Authentication
The reference documents trust authentication for PostgreSQL branches using IAM sources. Clients reaching those branch databases can supply arbitrary credentials, potentially accessing copied application data.
The comments explicitly state that the default accepts any credentials and describe a password alternative. This risk requires IAM-backed branching and network reachability.
Medium
API Service Certificate Verification Disabled by Default
The supplied defaults set tls.apiService.insecureSkipTLSVerify to true. Deployments retaining this setting cannot authenticate the operator server certificate, allowing impersonation by an attacker controlling the network path.
The active YAML setting explicitly disables verification. The troubleshooting guide recommends verification with a trusted certificate, but installation does not require that override.
Medium
Agent Transport Encryption Disabled by Default
Agent TLS defaults to false, leaving operator-to-agent traffic without this transport protection. Without compensating network encryption, an attacker on the traffic path could observe sensitive session data.
Both references explicitly identify TLS as optional and disabled by default. Actual exposure depends on network controls outside these files.
Medium
Broad Secret Permissions Enabled by Default
The supplied values enable dbBranchingLiteralCredentials, documented as granting cluster-wide Secret permissions. Unnecessary permissions increase the impact of operator compromise beyond namespaces requiring database branching.
The active default and accompanying documentation identify cluster-wide Secret permissions. Chart templates are not supplied, so exact granted verbs were not verified.
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
High
Generic API/secret keys
- **Inline (dev/test only)** — `cloud.apiKey.key: <YOUR_API_KEY>` (lands in the pod spec as plaintex
This option places a real cloud API key in plaintext pod configuration when used. The development-only warning reduces exposure but does not prevent credential disclosure.
High
Generic API/secret keys
This endpoint needs no authentication and no credit card. The response is a provisional organization
The signup response contains an api_key, but the preceding curl command sends its body directly to stdout. Running that example exposes credentials in tool output despite the prose warning.
Medium
Hardcoded URL
# licenseServer: http://mirrord-operator-license-server.mirrord.svc
The example uses HTTP for a license server authenticated with a shared license key. Without an encrypted network layer, on-path observers can capture that credential.
Medium
Hardcoded URL
- **License server** (fully self-hosted) — set `license.licenseServer: http://mirrord-operator-licen
The example uses HTTP for a license server authenticated with a shared license key. Without an encrypted network layer, on-path observers can capture that credential.
Risk Factors
🌐 Network access (29)
README.md:38 README.md:40 references/values.yaml:400 references/values.yaml:425 references/values.yaml:453 references/values.yaml:462 references/values.yaml:499 references/values.yaml:506 references/values.yaml:512 references/values.yaml:516 references/values.yaml:557 references/values.yaml:641 references/values.yaml:1261 references/values.yaml:1301 references/values.yaml:628 SKILL.md:55 SKILL.md:56 SKILL.md:66 SKILL.md:73 SKILL.md:75 SKILL.md:82 SKILL.md:147 SKILL.md:179 SKILL.md:185 SKILL.md:207 SKILL.md:269 SKILL.md:270 SKILL.md:271 SKILL.md:272
⚙️ External commands (50)
references/values.yaml:54 references/values.yaml:116 references/values.yaml:118 references/values.yaml:120 references/values.yaml:122 references/values.yaml:124 references/values.yaml:126 references/values.yaml:128 references/values.yaml:130 references/values.yaml:132 references/values.yaml:134 references/values.yaml:139 references/values.yaml:141 references/values.yaml:144 references/values.yaml:146 references/values.yaml:148 references/values.yaml:150 references/values.yaml:152 references/values.yaml:154 references/values.yaml:156 references/values.yaml:158 references/values.yaml:160 references/values.yaml:162 references/values.yaml:164 references/values.yaml:166 references/values.yaml:168 references/values.yaml:171 references/values.yaml:174 references/values.yaml:176 references/values.yaml:182 references/values.yaml:189 references/values.yaml:190 references/values.yaml:192 references/values.yaml:195 references/values.yaml:200 references/values.yaml:214 references/values.yaml:228 references/values.yaml:230 references/values.yaml:239 references/values.yaml:241 references/values.yaml:244 references/values.yaml:247 references/values.yaml:251 references/values.yaml:253 references/values.yaml:259 references/values.yaml:268 references/values.yaml:278 references/values.yaml:308 references/values.yaml:316 references/values.yaml:317
📁 Filesystem access (1)
🔑 Env variables (3)
Audited by: codex