backlog
The skill has documented allowed-tools declarations but contains undeclared kubectl/K3s pod execution capabilities that inject base64-encoded Python into Plane's API pod via django-shell, representing significant shadow functionality not covered in SKILL.md.
SKILL.md declares 'Bash(python3:*)' only, but plane_create_issue.py and plane_create_entity.py contain create_via_k3s_fallback() which executes kubectl exec to run Python code inside Plane API pods via django-shell. This is shell:ADMIN equivalent access to the Plane infrastructure.
scripts/plane_create_issue.py:303 Why this conclusion was reached
2/4 dimensions flagged4 undeclared or violating capabilities were inferred.
22 lower-risk artifacts were extracted and still need context.
The report includes 0 attack-chain steps and 2 severe findings.
Dependencies are present but no obvious high-risk issue stands out.
What drove the risk score up
SKILL.md declares only Bash(python3:*) but code uses kubectl exec to inject Python into Plane pods — shell:ADMIN equivalent not declared
Python scripts are base64-encoded and executed inside K8s pods via django-shell; obfuscation vector not documented
intake.py and prune_p2p3.py contain hardcoded C:\Users paths exposing system configuration
Most important evidence
Undeclared K3s/kubectl shell execution
SKILL.md declares 'Bash(python3:*)' only, but plane_create_issue.py and plane_create_entity.py contain create_via_k3s_fallback() which executes kubectl exec to run Python code inside Plane API pods via django-shell. This is shell:ADMIN equivalent access to the Plane infrastructure.
scripts/plane_create_issue.py:303 Base64-encoded Python injection into K8s pods
The K3s fallback builds Python scripts via f-strings then base64-encodes them before execution via kubectl exec django-shell. This pattern matches high-risk indicator behavior even though the injected code is benign.
scripts/plane_create_issue.py:269 Hardcoded Windows paths leak system configuration
intake.py DEFAULT_FIX_PLAN and prune_p2p3.py target file candidates contain hardcoded C:\Users paths (DAEGUNSOFT) revealing usernames, home directory structure, and development tooling preferences.
scripts/intake.py:22 K3s defaults target wrong namespace across clusters
K3s fallback defaults k3s_namespace to 'plane-ce' and workload to 'deploy/plane-api-wl', but the comments admit this is wrong for es6.kr cluster. Missing per-workspace config silently fails or targets wrong deployment.
scripts/plane_create_issue.py:296 Windows registry credential access
intake.py get_api_key() reads DGS_PLANE_API_KEY from Windows registry HKEY_CURRENT_USER\Environment if not in environment variables. Registry access for credentials not declared in SKILL.md.
scripts/intake.py:38 SKILL.md does not document Plane integration
SKILL.md describes the skill as 'vendor-agnostic' with 'abstract Receiver Contracts', but the actual implementation hardcodes plane.dgs.ai.kr URLs and workspace names. This creates a misleading impression of flexibility.
SKILL.md:62 Declared capability vs actual capability
SKILL.md declares Write tool; code modifies fix_plan.md plane_create_issue.py:289 - POST to intake API creates issues plane_create_issue.py:303-307 - kubectl exec into K8s pods plane_client.py:140 - reads PLANE_API_KEY, PLANE_HOST, PLANE_WORKSPACE No skill invocation found No clipboard access No browser automation plane_create_issue.py:303-307 - creates Issue records via Django ORM inside Plane pod Suspicious artifacts and egress
https://keepachangelog.com/en/1.0.0/ CHANGELOG.md:5
https://semver.org/spec/v2.0.0.html CHANGELOG.md:6
https://plane.es6.kr/es6kr/projects/ comment.md:47
https://plane.dgs.ai.kr/dgs/projects/ create.md:109
https://plane.dgs.ai.kr/dgs/browse/ create.md:109
https://plane.dgs.ai.kr/dgs/browse/INFRA-77 create.md:110
https://plane.dgs.ai.kr/api/v1/workspaces/dgs scripts/intake.py:21
https://plane.dgs.ai.kr/dgs/browse/ES6KR-128 scripts/plane_verify_identifier.py:15
https://plane.dgs.ai.kr scripts/test_plane_client_browse_url.py:28
https://plane.dgs.ai.kr/dgs/browse/INFRA-62 scripts/test_plane_client_browse_url.py:39
https://plane.example.com scripts/test_plane_client_intake.py:27
https://plane.dgs.ai.kr/dgs/browse/AIAUTO-176 scripts/test_plane_create_issue_browse_url.py:104
Dependencies and supply chain
| Package | Version | Source | Known vuln | Notes |
|---|---|---|---|---|
| urllib | stdlib | Python standard library | No | Standard library only, no external dependencies |
| json | stdlib | Python standard library | No | Standard library only |
| subprocess | stdlib | Python standard library | No | Used for kubectl exec - legitimate K8s tool integration |
File composition
scripts/plane_create_issue.py scripts/test_plane_sync.py scripts/intake.py create.md