Versioned security assessment

Report ID: SA-BAD9DAFC

9/29/2026, 9:57:00 PM

mirrord-prev-env security assessment v1

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: codex Latest published report
Skill name
mirrord-prev-env
Version
v2.5
Maintainer
metalbear-co
Coverage
2 Files scanned · 573 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

High

4 confirmed security findings require attention.

Installation context

Check the current Skill page

This page summarizes report evidence only. The Skill page provides the canonical install advisory.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

All 162 static matches are false positives involving Markdown syntax, documentation links, or expected setup operations. Four contextual risks remain: persistent CI credentials, mutable Action references, a missing trusted-PR guard, and traffic filters that match key prefixes. No evidence found of prompt injection, credential exfiltration, or malicious intent in the two reviewed files.

Report position

Latest published report

Latest refers to the report sequence, not to artifact currentness.

Audit attestation

Active attestation

A public attestation is available for this exact report.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

2 Files scanned · 573 Lines analyzed

4 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 13 evidence locations

Filesystem access

May read or write local files.

Observed in 3 evidence locations

Env variables

May read values from the process environment.

Observed in 1 evidence location

External commands

May invoke commands or programs outside the Skill.

Observed in 50 evidence locations

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (4)

RISK-001 High
Preview Workflow Omits the Required Trusted-PR Gate
The pull_request example starts previews whenever the event is not closed, without checking repository ownership or author approval. Where cluster credentials are available to fork jobs, copying this workflow can deploy untrusted PR images into the shared cluster.
The start condition lacks the trust check explicitly required elsewhere in the skill. Default GitHub fork-secret restrictions mitigate exposure, so exploitation depends on runner credentials and authentication configuration.
RISK-002 Medium
Persistent Cluster Credentials in the Primary CI Example
The setup creates a service-account-token Secret, extracts its token, and stores a reusable kubeconfig in CI. Unlike short-lived authentication, a stolen token remains usable until revoked, extending access to preview-management privileges.
The YAML explicitly creates a persistent service-account-token Secret and instructs storing its derived kubeconfig. OIDC is mentioned, but expiration and rotation are absent from this example.
RISK-003 Medium
Mutable Action References in Credentialed CI Workflows
Examples execute metalbear-co/mirrord-preview@main after configuring cluster access. A changed or compromised branch can execute different code with those credentials; the default CLI download adds another unpinned dependency.
The examples use @main rather than immutable revisions and describe automatic installation of the latest CLI. This establishes a supply-chain exposure, not evidence that upstream code is malicious.
RISK-004 Medium
Traffic Filters Do Not Enforce Complete Environment Keys
The example regex accepts any suffix after alice-checkout-fix, while CI filters substitute a key without an ending boundary. A longer key sharing that prefix can match another preview filter and misroute requests, weakening the documented session isolation.
The ad-hoc regex explicitly ends its key match with .*, and the CI regex has no complete-member boundary. Prefix collisions follow directly from these documented regex patterns.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    The preview-start example lacks the trusted-PR restriction required by the security guidance.
    Add an explicit same-repository or approved-author gate before cluster authentication and deployment; do not grant cluster credentials to untrusted PR jobs.
  2. FIX-002
    Medium
    The CI setup creates a persistent service-account token despite recommending short-lived credentials.
    Make OIDC or expiring TokenRequest credentials the primary example; document expiration, rotation, revocation, and runner cleanup for any stored-token fallback.
  3. FIX-003
    Medium
    Workflow examples run the preview Action from a mutable main branch with cluster credentials available.
    Pin Actions to reviewed commit hashes and use cli_path with a verified CLI in a trusted runner image.
  4. FIX-004
    Medium
    Example header filters can match environment keys with additional suffixes.
    Escape keys for regex use and require complete baggage-member boundaries; test prefix collisions, extra members, whitespace, and similar keys.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2
Content hash
d312dce595adb9b42632433fafff435ef1a278d0bb0ac1e80c22a0b4b2773a69
Tree hash
08a04f1c0895961601a269c06d8793c922342be0534628fa2a8c05dfcd649dcf
Skill path
skills/metalbear-co/mirrord-prev-env
Audit payload hash
7a4bde5effda237c73ed27bb0b0149b0

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: active