Versioned security assessment

Report ID: SA-BAD9DAFC

9/29/2026, 10:08:36 PM

mirrord-temporal security assessment v1

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: codex Latest published report
Skill name
mirrord-temporal
Version
v1.2
Maintainer
metalbear-co
Coverage
4 Files scanned Β· 604 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

High

2 confirmed security findings require attention.

Installation context

Check the current Skill page

This page summarizes report evidence only. The Skill page provides the canonical install advisory.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

The static matches are mostly false positives caused by Markdown backticks, shell examples, placeholder certificate names, and secret-reference documentation. The skill still presents operational risk because it permits broad cluster discovery and mentions agent-directed operator installation, which require explicit authorization and least-privilege controls.

Report position

Latest published report

Latest refers to the report sequence, not to artifact currentness.

Audit attestation

Active attestation

A public attestation is available for this exact report.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

4 Files scanned Β· 604 Lines analyzed

2 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Not recorded by this audit

Filesystem access

May read or write local files.

Observed in 9 evidence locations

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 50 evidence locations

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (2)

RISK-001 High
Agent-Directed Cluster Installation
The skill tells an AI agent that it may start a trial and install the mirrord operator after user agreement. Installing an operator changes cluster state and can grant broad control-plane access, so the action requires explicit confirmation and least-privilege review.
The instruction explicitly describes starting a trial and installing an operator. The operational impact is clear, although it requires user agreement and refers to another skill for the procedure.
RISK-002 Medium
Broad Cluster Discovery
The discovery workflow queries namespaces, workloads, CRDs, resources across all namespaces, deployment YAML, and services. These read-only queries can expose cluster topology and configuration metadata, so output handling and RBAC scope require controls.
The referenced commands visibly inspect multiple cluster-wide resource types. They are read-only, but the breadth of metadata access creates a confidentiality and least-privilege concern.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    The skill allows an AI agent to offer a trial and install the mirrord operator after user agreement.
    Require a separate explicit confirmation before any cluster change, show the exact commands, and verify namespace, RBAC scope, chart source, and rollback steps.
  2. FIX-002
    High
    Credential and certificate examples could be copied into generated configuration incorrectly.
    Keep all credential examples non-secret, require Kubernetes secret references, and warn users not to paste secret values into prompts or generated output.
  3. FIX-003
    Medium
    Auto-discovery queries workloads, services, CRDs, and resources across all namespaces.
    Make discovery opt-in, limit it to named namespaces and resources, use least-privilege RBAC, and redact returned configuration before displaying it.
  4. FIX-004
    Medium
    Task routing and immediate teardown can affect production work.
    Recommend non-production testing, explicit filter review, bounded buffering, and a nonzero drain timeout when in-flight work must be preserved.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2
Content hash
e3b0415e974a1e241bfb971ef08eaf280c13052fef9a4f4d23ead019fad0225e
Tree hash
183a575ea156425185d3bbb74b4d76be23d7ea4c7eb14eadb02d50ebeab950ad
Skill path
skills/metalbear-co/mirrord-temporal
Audit payload hash
20458bed85decf4cbc7ddf5133b93626

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: active