Skill Trust Decision

backlog

The skill has documented allowed-tools declarations but contains undeclared kubectl/K3s pod execution capabilities that inject base64-encoded Python into Plane's API pod via django-shell, representing significant shadow functionality not covered in SKILL.md.

Install decision first Source: ClawHub Scanned: 17 hr ago
Files 25
Artifacts 22
Violations 4
Findings 6
Most direct threat evidence
High Doc Mismatch
Undeclared K3s/kubectl shell execution

SKILL.md declares 'Bash(python3:*)' only, but plane_create_issue.py and plane_create_entity.py contain create_via_k3s_fallback() which executes kubectl exec to run Python code inside Plane API pods via django-shell. This is shell:ADMIN equivalent access to the Plane infrastructure.

scripts/plane_create_issue.py:303

Why this conclusion was reached

2/4 dimensions flagged
Block
Declared vs actual capability

4 undeclared or violating capabilities were inferred.

Review
Hidden execution and egress

22 lower-risk artifacts were extracted and still need context.

Block
Attack chain and severe findings

The report includes 0 attack-chain steps and 2 severe findings.

Pass
Dependencies and supply chain hygiene

Dependencies are present but no obvious high-risk issue stands out.

What drove the risk score up

Undeclared K3s/kubectl execution +20

SKILL.md declares only Bash(python3:*) but code uses kubectl exec to inject Python into Plane pods — shell:ADMIN equivalent not declared

Base64-encoded script injection +15

Python scripts are base64-encoded and executed inside K8s pods via django-shell; obfuscation vector not documented

Hardcoded Windows paths +10

intake.py and prune_p2p3.py contain hardcoded C:\Users paths exposing system configuration

Most important evidence

High Doc Mismatch

Undeclared K3s/kubectl shell execution

SKILL.md declares 'Bash(python3:*)' only, but plane_create_issue.py and plane_create_entity.py contain create_via_k3s_fallback() which executes kubectl exec to run Python code inside Plane API pods via django-shell. This is shell:ADMIN equivalent access to the Plane infrastructure.

scripts/plane_create_issue.py:303
Declare shell:ADMIN capability and document the K3s fallback mechanism with clear scope boundaries.
High Obfuscation

Base64-encoded Python injection into K8s pods

The K3s fallback builds Python scripts via f-strings then base64-encodes them before execution via kubectl exec django-shell. This pattern matches high-risk indicator behavior even though the injected code is benign.

scripts/plane_create_issue.py:269
Document base64 usage or consider alternative approaches that don't match obfuscation signatures.
Medium Sensitive Access

Hardcoded Windows paths leak system configuration

intake.py DEFAULT_FIX_PLAN and prune_p2p3.py target file candidates contain hardcoded C:\Users paths (DAEGUNSOFT) revealing usernames, home directory structure, and development tooling preferences.

scripts/intake.py:22
Remove hardcoded paths; use only environment variables or CLI arguments for file paths.
Medium Priv Escalation

K3s defaults target wrong namespace across clusters

K3s fallback defaults k3s_namespace to 'plane-ce' and workload to 'deploy/plane-api-wl', but the comments admit this is wrong for es6.kr cluster. Missing per-workspace config silently fails or targets wrong deployment.

scripts/plane_create_issue.py:296
Fail loudly if k3s_namespace/k3s_workload are not explicitly configured rather than using wrong defaults.
Medium Credential Theft

Windows registry credential access

intake.py get_api_key() reads DGS_PLANE_API_KEY from Windows registry HKEY_CURRENT_USER\Environment if not in environment variables. Registry access for credentials not declared in SKILL.md.

scripts/intake.py:38
Document credential retrieval from Windows registry or deprecate this fallback in favor of standard environment variable access.
Low Doc Mismatch

SKILL.md does not document Plane integration

SKILL.md describes the skill as 'vendor-agnostic' with 'abstract Receiver Contracts', but the actual implementation hardcodes plane.dgs.ai.kr URLs and workspace names. This creates a misleading impression of flexibility.

SKILL.md:62
Document the actual Plane vendor lock-in or make integration truly configurable.

Declared capability vs actual capability

Filesystem Pass
Declared WRITE
→
Inferred WRITE
SKILL.md declares Write tool; code modifies fix_plan.md
Network Block
Declared READ
→
Inferred WRITE
plane_create_issue.py:289 - POST to intake API creates issues
Shell Block
Declared WRITE
→
Inferred ADMIN
plane_create_issue.py:303-307 - kubectl exec into K8s pods
Environment Block
Declared NONE
→
Inferred READ
plane_client.py:140 - reads PLANE_API_KEY, PLANE_HOST, PLANE_WORKSPACE
Skill Invoke Pass
Declared NONE
→
Inferred NONE
No skill invocation found
Clipboard Pass
Declared NONE
→
Inferred NONE
No clipboard access
Browser Pass
Declared NONE
→
Inferred NONE
No browser automation
Database Block
Declared NONE
→
Inferred WRITE
plane_create_issue.py:303-307 - creates Issue records via Django ORM inside Plane pod

Suspicious artifacts and egress

Medium External URL
https://keepachangelog.com/en/1.0.0/

CHANGELOG.md:5

Medium External URL
https://semver.org/spec/v2.0.0.html

CHANGELOG.md:6

Medium External URL
https://plane.es6.kr/es6kr/projects/

comment.md:47

Medium External URL
https://plane.dgs.ai.kr/dgs/projects/

create.md:109

Medium External URL
https://plane.dgs.ai.kr/dgs/browse/

create.md:109

Medium External URL
https://plane.dgs.ai.kr/dgs/browse/INFRA-77

create.md:110

Medium External URL
https://plane.dgs.ai.kr/api/v1/workspaces/dgs

scripts/intake.py:21

Medium External URL
https://plane.dgs.ai.kr/dgs/browse/ES6KR-128

scripts/plane_verify_identifier.py:15

Medium External URL
https://plane.dgs.ai.kr

scripts/test_plane_client_browse_url.py:28

Medium External URL
https://plane.dgs.ai.kr/dgs/browse/INFRA-62

scripts/test_plane_client_browse_url.py:39

Medium External URL
https://plane.example.com

scripts/test_plane_client_intake.py:27

Medium External URL
https://plane.dgs.ai.kr/dgs/browse/AIAUTO-176

scripts/test_plane_create_issue_browse_url.py:104

Dependencies and supply chain

PackageVersionSourceKnown vulnNotes
urllib stdlib Python standard library No Standard library only, no external dependencies
json stdlib Python standard library No Standard library only
subprocess stdlib Python standard library No Used for kubectl exec - legitimate K8s tool integration

File composition

25 files · 6146 lines
Python 17 files · 5635 linesMarkdown 6 files · 485 linesOther 1 files · 21 linesJSON 1 files · 5 lines
Files of concern · 4
scripts/plane_create_issue.py Python · 709 lines
Undeclared K3s/kubectl shell execution · Base64-encoded Python injection into K8s pods · K3s defaults target wrong namespace across clusters
scripts/test_plane_sync.py Python · 513 lines
https://plane.example.com/myworkspace/projects/ · http://plane.example.com · https://evil.example
scripts/intake.py Python · 327 lines
Hardcoded Windows paths leak system configuration · Windows registry credential access · https://plane.dgs.ai.kr/api/v1/workspaces/dgs
create.md Markdown · 110 lines
https://plane.dgs.ai.kr/dgs/projects/ · https://plane.dgs.ai.kr/dgs/browse/ · https://plane.dgs.ai.kr/dgs/browse/INFRA-77
Other files · plane_create_entity.py · plane_sync.py · plane_client.py · plane_update_entity.py · plane_bulk_update.py · prune_p2p3.py +2

Security positives

HTTPS enforcement in plane_create_issue.py refuses non-HTTPS hosts (CWE-319)
Redirect protection via add_unredirected_header prevents credential forwarding to attacker-controlled hosts
Non-HTTPS check in plane_sync.py make_plane_request() with explicit error message
_NoRedirect handler in plane_sync.py blocks redirect-based credential theft
Idempotency guards prevent duplicate issue creation
Comprehensive error handling with specific error messages
Rate limiting with HTTP 429 backoff protects against API abuse
Dry-run modes in sync and prune operations allow safe preview