Back to skill

Security audit

Git Plus

Security checks for vulnerabilities and agentic risk

Overview

This is a Git workflow reference skill with disclosed, purpose-aligned examples, but users should review hook and deploy commands before running them.

Install only if you want a Git command reference skill. Before following its examples, pin or use locally installed Husky, review any generated hooks, and treat CI deploy snippets as templates that can change remote environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:159
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:159-160
Vulnerability Type: Supply-chain risk from unpinned package retrieval and execution
Risk Level: Medium

Vulnerable Code:

bash
npx husky install
npx husky add .git/hooks/pre-commit "npm run lint"

Technical Analysis

The documented commands invoke husky through npx without specifying an exact, reviewed version or requiring an already-installed local dependency. If Husky is not available locally, npx may retrieve the package from the configured package registry and execute it immediately.

Consequently, the code executed by these commands is not fully determined by the reviewed Skill text. Package updates, registry compromise, unsafe registry configuration, or dependency-resolution manipulation could cause an unexpected package version to run with the invoking user's permissions. Package lifecycle scripts and the CLI itself may execute arbitrary code. The commands are also intended to alter Git hook configuration, which can cause code to run during later Git operations.

Attack Path

  1. A user follows the instructions in SKILL.md to install Git hooks.
  2. The requested husky executable is not present in the project's local dependencies.
  3. npx resolves and downloads a package from the user's configured package registry without enforcing a reviewed version.
  4. A compromised, substituted, or unexpectedly changed package executes its lifecycle or CLI code under the user's account.
  5. The package can access resources available to that process and may modify the repository or its Git hook configuration.
  6. Malicious hook content could subsequently execute when affected Git operations occur.

Impact Assessment

Successful exploitation would provide code execution with the permissions of the user running npx. The accessible scope may include the current repository, writable files available to that user, environment variables ...[truncated 345 chars]

Remediation
View remediation

Remediation Suggestions

  • Declare Husky as a development dependency using an audited, exact version.
  • Commit the package manifest and lockfile, and install dependencies with npm ci.
  • Invoke only the locally installed package, such as with npx --no-install husky, or use a package-manager script that resolves the locked local binary.
  • Configure CI to reject unexpected lockfile changes and use dependency integrity verification.
  • Review all generated or modified Git hooks before enabling them.
  • Regularly scan the locked dependency tree and apply updates through a controlled review process.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill recommends running npx husky install without pinning a version, which can fetch and execute whatever version is current at runtime. That creates a supply-chain risk: a malicious or compromised upstream release could execute arbitrary code on the user's machine during hook setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The command npx husky add .git/hooks/pre-commit "npm run lint" invokes an unpinned package from the registry, again allowing arbitrary code execution from an unexpected package version. Because npx may download and run code immediately, this is a real supply-chain exposure rather than a purely stylistic issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown includes CI/CD deploy steps such as npm run deploy in both GitHub Actions and GitLab CI examples, which may modify production or staging environments. The surrounding documentation does not include any warning, caution note, or disclosure that these commands can trigger remote changes and should be reviewed before use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.