Back to skill

Security audit

GitCode PR comment fix

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently fetches GitCode PR review comments, helps apply user-approved local code fixes, and optionally replies or resolves discussions with confirmation, but users should handle tokens and PR context carefully.

Install only if you intend to let the agent work with GitCode PR review comments. Use a narrowly scoped GITCODE_TOKEN through the environment, do not paste tokens into chat or command lines, review the summarized comment list before approving code edits, and confirm any reply or resolve action before it changes the live PR discussion. Treat generated context JSON and terminal logs as potentially confidential PR data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:16
Finding

Access Token Exposure Through Chat and Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/pr_comment_fix_tool.py:42
Finding

Private PR Context Is Duplicated to Standard Output and Written Without Explicitly Restrictive Permissions

Content
View full analysis
None: text = json.dumps(data, ensure_ascii=False, indent=2) + "\n" if outfile: with open(outfile, "w", encoding="utf-8") as f: f.write(text) try: sys.stdout.buffer.write(text.encode("utf-8")) sys.stdout.buffer.flush() except (AttributeError, OSError): print(text, end="") ``` The behavior is invoked for fetched PR context at `scripts/pr_comment_fix_tool.py:248-250`: ```python if out_path: _print_json(payload, outfile=out_path) sys.stderr.write("已写入: %s\n" % os.path.abspath(out_path)) ``` ### Technical Analysis When an output path is supplied, `_print_json` writes the complete payload to that file and then prints the same payload to standard output. The payload can contain private PR titles, repository identifiers, file paths, full review-comment bodies, discussion identifiers, and raw API response fields. In agent, CI, and automation environments, standard output is commonly captured in persistent logs. Consequently, using `--output` does not prevent sensitive PR data from entering logs. The output file is created with Python's ordinary `open(..., "w")`, so its effective permissions depend on the process umask and any preexisting file. The implementation does not enforce owner-only access. The supplied `.gitignore` reduces accidental commits only for `pr_comment_fix_context.json` and `*_pr_comment_fix_context.json`; users may select arbitrary output filenames and locations. No GitCode token is included in the generated JSON based on the audited implementation. The exposed information is PR context rathe ...[truncated 1233 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
**SKILL_ROOT**:本 `SKILL.md` 所在目录。

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says the skill is for modifying code according to GitCode PR review comments, implying code changes are its primary behavior. The implementation and module docstring show only PR comment retrieval, discussion replies, and resolution-state updates via API calls, with no code parsing, patch generation, or file modification logic anywhere in the script.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill requires access to environment secrets, network calls, shell execution, and file modification, but it does not declare an explicit tool/permission scope. That creates an authorization ambiguity where an agent may use more capability than a reviewer or platform policy expects, especially since the workflow fetches remote PR data and then edits local code based on it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

User-facing descriptions, help text, and error messages throughout the file are all in Chinese, with no indication that the tool is region-specific or that another language is supported. This creates a natural-language policy concern because it imposes a specific language on users without opt-in or documented justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/pr_comment_fix_tool.py (reported line 27)May include surrounding context.

python
from urllib.parse import quote, urlencode
from urllib.request import Request, urlopen

GITCODE_API_BASE = "https://api.gitcode.com/api/v5"
API_RETRY = 2
API_RETRY_INTERVAL = 2.0

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/pr_comment_fix_tool.py (reported line 62)May include surrounding context.

python
if sys.platform == "win32":
        for scope in ("User", "Machine"):
            try:
                out = subprocess.check_output(
                    [
                        "powershell",
                        "-NoProfile",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The tool performs authenticated state-changing actions on PR discussions, including marking threads resolved, without an explicit confirmation step or strong user-facing warning. In an agent context, this increases the risk of unintended workflow manipulation, especially if a user or upstream prompt ambiguously requests review handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README tells users to create and export a GitCode personal access token, but it does not clearly warn that the skill will authenticate to GitCode and perform remote actions such as fetching PR discussion context and optionally posting replies or changing resolution state. This is dangerous because users may provide high-privilege credentials without understanding the scope of remote API access or the consequences of running the tool against a live repository service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description hard-codes Chinese phrasing together with English tokens ('Use when 用户要修改 PR 检视意见') and the rest of the skill instructions are written in Chinese, which implies a locale preference without explicit user opt-in. Under the policy rule, language constraints should either be optional or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.