Back to skill

Security audit

Code Graph(代码图谱)

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for setting up GitNexus, but it includes risky fallback and troubleshooting commands that can execute unpinned packages and commit all local files.

Review before installing. Prefer the pinned global install path or an explicitly pinned `npx gitnexus@1.6.5` command, and avoid the suggested `git add . && git commit` workflow unless you have reviewed `.gitignore`, checked `git status`, and confirmed no secrets or private files will be committed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:77
Finding

Unpinned GitNexus Package Execution Through npx

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:188
Finding

Unrestricted Staging and Committing of Project Files

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The troubleshooting instructions suggest git init && git add . && git commit without warning that this stages and records all current files, potentially including secrets, credentials, build artifacts, or proprietary data. In the context of a setup skill, users may not expect a version-control action that permanently snapshots their working directory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description defines invocation phrases only in Chinese, which imposes a specific language requirement without indicating user opt-in or multilingual alternatives. This is a natural-language policy issue because the skill appears constrained to one language without documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advertises one-click installation, MCP configuration, and code graph construction without an upfront warning that it will globally install software and write configuration. This can lead users to approve system-level and editor-level changes without informed consent, increasing the risk of unsafe execution in sensitive environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill recommends npx gitnexus as a fallback without pinning an exact package version. npx may fetch the latest package from the registry at execution time, creating a supply-chain risk where a malicious or compromised upstream release could be executed on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This fallback command uses npx gitnexus setup without a pinned version, which can download and execute whatever package version is current at runtime. Because setup writes MCP/editor configuration, a compromised package could modify global developer tooling configuration unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using npx gitnexus status without a version pin exposes users to execution of unreviewed upstream code fetched at runtime. Even a seemingly read-only status command still executes package code locally and can be abused if the package supply chain is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill again falls back to npx gitnexus setup without version pinning. In context, this is particularly risky because the command modifies MCP/editor configuration globally, so a malicious package version could persistently alter developer environment settings.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The unpinned npx gitnexus status fallback repeats the same package resolution risk later in the workflow. Because the skill is intended for one-click setup, users are likely to execute commands verbatim, increasing the chance of silent supply-chain compromise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs initializing a new Git repository and making an initial commit as part of troubleshooting, which goes beyond the scoped task of installing/configuring GitNexus. This broadens the action surface to repository state changes and can unintentionally capture and stage sensitive files unrelated to the user's intent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The troubleshooting section recommends npx gitnexus analyze without pinning a version, allowing untrusted code retrieval and execution from the package registry. Since analyze scans the full repository and accesses source files, a malicious package could exfiltrate sensitive code or credentials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.