Versioned security assessment

Report ID: SA-BAD9DAFC

9/29/2026, 9:50:06 PM

mirrord-operator security assessment v1

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: codex Latest published report
Skill name
mirrord-operator
Version
v2.14
Maintainer
metalbear-co
Coverage
5 Files scanned · 2,000 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

High

14 confirmed security findings require attention.

Installation context

Check the current Skill page

This page summarizes report evidence only. The Skill page provides the canonical install advisory.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Most alerts are false positives from Markdown formatting, YAML comments, and legitimate configuration references. Confirmed risks involve inline credentials, trial response exposure, and HTTP licensing; additional findings address transport security, database authentication, and excessive permissions. No evidence found of prompt injection or malicious intent; cluster changes and trial registration explicitly require user approval.

Report position

Latest published report

Latest refers to the report sequence, not to artifact currentness.

Audit attestation

Active attestation

A public attestation is available for this exact report.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

5 Files scanned · 2,000 Lines analyzed

18 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 29 evidence locations

Filesystem access

May read or write local files.

Observed in 1 evidence location

Env variables

May read values from the process environment.

Observed in 3 evidence locations

External commands

May invoke commands or programs outside the Skill.

Observed in 50 evidence locations

Capability review items (4)
High
Generic API/secret keys
- **Inline (dev/test only)** — `cloud.apiKey.key: <YOUR_API_KEY>` (lands in the pod spec as plaintex
This option places a real cloud API key in plaintext pod configuration when used. The development-only warning reduces exposure but does not prevent credential disclosure.
High
Generic API/secret keys
This endpoint needs no authentication and no credit card. The response is a provisional organization
The signup response contains an api_key, but the preceding curl command sends its body directly to stdout. Running that example exposes credentials in tool output despite the prose warning.
Medium
Hardcoded URL
# licenseServer: http://mirrord-operator-license-server.mirrord.svc
The example uses HTTP for a license server authenticated with a shared license key. Without an encrypted network layer, on-path observers can capture that credential.
Medium
Hardcoded URL
- **License server** (fully self-hosted) — set `license.licenseServer: http://mirrord-operator-licen
The example uses HTTP for a license server authenticated with a shared license key. Without an encrypted network layer, on-path observers can capture that credential.

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (14)

RISK-001 High
Certificate/key files
| `cloud.apiKey.key` | Inline value — plaintext in the pod spec. Dev/test only. |
This option places a real cloud API key in plaintext pod configuration when used. The development-only warning reduces exposure but does not prevent credential disclosure.
RISK-002 High
Certificate/key files
| `license.key` | Inline license key. Deprecated for cloud; still the shared secret for a self-hoste
The documented license.key option embeds a shared authentication secret in Helm values when followed. This can expose credentials through configuration storage or accidental commits despite safer alternatives.
RISK-003 High
Certificate/key files
| `license.file.secret.data.license.pem` | Inline PEM as a YAML literal block (air-gapped). |
The inline example places offline license material in Helm values, contrary to the skill's secret-handling boundary. Following it can expose licensing material through shared configuration.
RISK-004 High
Certificate/key files
- **Cloud API key (default):** the operator exchanges a cloud API key for a license over the API. Pr
This option places a real cloud API key in plaintext pod configuration when used. The development-only warning reduces exposure but does not prevent credential disclosure.
RISK-005 High
Certificate/key files
- **License key (deprecated for cloud):** `license.key` / `license.keyRef` (Secret data key `OPERATO
The documented license.key option embeds a shared authentication secret in Helm values when followed. This can expose credentials through configuration storage or accidental commits despite safer alternatives.
RISK-006 High
Certificate/key files
- **Air-gapped:** offline PEM (`license.file.secret.data.license.pem` or `license.pemRef`) or a `lic
The inline example places offline license material in Helm values, contrary to the skill's secret-handling boundary. Following it can expose licensing material through shared configuration.
RISK-007 High
Certificate/key files
- **Inline (dev/test only)** — `cloud.apiKey.key: <YOUR_API_KEY>` (lands in the pod spec as plaintex
This option places a real cloud API key in plaintext pod configuration when used. The development-only warning reduces exposure but does not prevent credential disclosure.
RISK-008 High
Certificate/key files
**B. License key (deprecated for cloud auth).** Still valid for existing installs and **required** w
The documented license.key option embeds a shared authentication secret in Helm values when followed. This can expose credentials through configuration storage or accidental commits despite safer alternatives.
RISK-009 High
Certificate/key files
license.pem: |
The inline example places offline license material in Helm values, contrary to the skill's secret-handling boundary. Following it can expose licensing material through shared configuration.
RISK-010 High
Certificate/key files
<contents of your license.pem>
The inline example places offline license material in Helm values, contrary to the skill's secret-handling boundary. Following it can expose licensing material through shared configuration.
RISK-011 High
IAM Database Branches Default to Trust Authentication
The reference documents trust authentication for PostgreSQL branches using IAM sources. Clients reaching those branch databases can supply arbitrary credentials, potentially accessing copied application data.
The comments explicitly state that the default accepts any credentials and describe a password alternative. This risk requires IAM-backed branching and network reachability.
RISK-012 Medium
API Service Certificate Verification Disabled by Default
The supplied defaults set tls.apiService.insecureSkipTLSVerify to true. Deployments retaining this setting cannot authenticate the operator server certificate, allowing impersonation by an attacker controlling the network path.
The active YAML setting explicitly disables verification. The troubleshooting guide recommends verification with a trusted certificate, but installation does not require that override.
RISK-013 Medium
Agent Transport Encryption Disabled by Default
Agent TLS defaults to false, leaving operator-to-agent traffic without this transport protection. Without compensating network encryption, an attacker on the traffic path could observe sensitive session data.
Both references explicitly identify TLS as optional and disabled by default. Actual exposure depends on network controls outside these files.
RISK-014 Medium
Broad Secret Permissions Enabled by Default
The supplied values enable dbBranchingLiteralCredentials, documented as granting cluster-wide Secret permissions. Unnecessary permissions increase the impact of operator compromise beyond namespaces requiring database branching.
The active default and accompanying documentation identify cluster-wide Secret permissions. Chart templates are not supplied, so exact granted verbs were not verified.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    Inline authentication examples conflict with the stated secret-handling rules.
    Remove inline API key, license key, and license PEM examples from operational guidance. Use Kubernetes Secret or Google Secret Manager references consistently.
  2. FIX-002
    High
    The trial signup command prints a response containing an API key.
    Capture the response in a permission-restricted temporary file outside agent output. Parse it locally, transfer credentials securely, redact displayed fields, and remove temporary data.
  3. FIX-003
    High
    IAM-backed PostgreSQL branches are documented to accept arbitrary credentials by default.
    Recommend password authentication for IAM-backed branches and restrict network access to authorized workloads. Explain the trust-mode exposure before enabling branching.
  4. FIX-004
    Medium
    Self-hosted license server examples use HTTP for shared-secret authentication.
    Use HTTPS with a trusted certificate, or explicitly require an authenticated encrypted transport before sharing the license key.
  5. FIX-005
    Medium
    API service certificate verification and agent transport encryption are disabled in the supplied defaults.
    Document a production override enabling agent TLS and API service certificate verification. Provision trusted certificates and verify connectivity before rollout.
  6. FIX-006
    Medium
    Literal database credentials enable cluster-wide Secret permissions by default.
    Recommend disabling dbBranchingLiteralCredentials unless required. Use existing Secret references and review rendered RBAC permissions before installation.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2
Content hash
4aa6afedc2167d9bc8fb8ffdda4dd46dcd8424eca79c4e55d02351fd4f680b83
Tree hash
defb5cb35dd0ac260d137f982d67956ff29b488b49580a9f112bf2b6bd8a50f4
Skill path
skills/metalbear-co/mirrord-operator
Audit payload hash
0ea9211df6ba2ca87d2b01900e948402

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: active