Back to skill

Security audit

Github Stars Analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it handles GitHub tokens through command-line arguments and can overwrite arbitrary writable files, so users should review it before installing.

Install only if you are comfortable with an agent running this local Python script. Prefer unauthenticated use; if a token is needed, use a short-lived GitHub token with no permissions and avoid pasting valuable PATs into command arguments. Keep output paths inside a dedicated reports folder and avoid running it on untrusted usernames or instructions that supply paths.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_stars.py:329
Finding

GitHub Personal Access Token Exposed Through Command-Line Arguments

Content
View full analysis
[--token ] [--output ] Examples: python3 fetch_stars.py blckrabbit python3 fetch_stars.py https://github.com/blckrabbit?tab=stars python3 fetch_stars.py blckrabbit --token ghp_xxx --output report.md """ ``` ```python def fetch_starred(username: str, token: str = None) -> list: """Call the GitHub API and retrieve all starred repositories page by page.""" headers = {"Accept": "application/vnd.github.star+json"} if token: headers["Authorization"] = f"Bearer {token}" ``` ```python parser.add_argument("--token", default=None, help="GitHub Personal Access Token (optional)") ``` The Skill documentation also directs users to provide a token through the same command-line option: ```bash python3 /home/claude/fetch_stars.py USERNAME --output /home/claude/USERNAME_github_stars.md ``` ```text --token : GitHub Personal Access Token ``` ### Technical Analysis The script accepts a GitHub Personal Access Token directly through the `--token` command-line argument. Command-line arguments are commonly observable through shell history, process inspection utilities, terminal transcripts, orchestration logs, and AI Agent tool-call records. The script uses the credential as an `Authorization: Bearer` header and sends it to the official HTTPS endpoint at `api.github.com`. This network transmission is consistent with the declared authenticated GitHub API functionality and does not constitute evidence of exfiltration to an unauthorized party. The security issue is the method used to ingest the credential before transmission. The authenticated request itself does not exceed the functional ...[truncated 1441 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_stars.py:329
Finding

Arbitrary File Overwrite Through Unrestricted Output Path

Content
View full analysis
str: """Extract a GitHub username from a URL or string.""" raw = raw.strip().rstrip("/") m = re.search(r"github\.com/([A-Za-z0-9_.-]+)", raw) if m: return m.group(1) if raw.startswith("@"): return raw[1:] return raw ``` ```python parser.add_argument("username", help="GitHub username or profile URL") parser.add_argument("--token", default=None, help="GitHub Personal Access Token (optional)") parser.add_argument("--output", default=None, help="Output file path (default: _github_stars.md)") args = parser.parse_args() username = parse_username(args.username) output = args.output or f"{username}_github_stars.md" print(f"🚀 Starting retrieval of {username}'s GitHub Stars...\n") repos = fetch_starred(username, token=args.token) print(f"\n✅ Retrieved {len(repos)} repositories; generating report...") report = render_report(username, repos) with open(output, "w", encoding="utf-8") as f: f.write(report) ``` ### Technical Analysis The `--output` option accepts an unrestricted path and passes it directly to `open(..., "w")`. Write mode creates a new file or truncates an existing file. The script does not resolve the destination, enforce an approved output directory, reject symbolic links, check whether the file already exists, or request explicit overwrite confirmation. The default output path also incorporates `username`. URL-derived usernames are constrained by the regular expression, but bare input is returned without validation. Consequently, path separators and traversal components can become part of the default destination. The appended `_github_stars.md` suffix limits which default-path filenames can be targeted, but it does not prevent writing outsi ...[truncated 1834 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill explicitly encourages supplying a GitHub Personal Access Token to the script, which creates a credential-handling path without any safeguards for secret collection, storage, redaction, or scope minimization. In an agent/tooling context, this can expose the token through command history, logs, process listings, or copied files, and the skill does not constrain how the token is provided.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

text

可选参数:
- `--token <PAT>`:GitHub Personal Access Token,将 API 限额从 60次/小时 提升至 5000次/小时
- `--output <路径>`:指定输出文件路径,默认为 `<username>_github_stars.md`

### 第三步:交付文件

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/fetch_stars.py (reported line 146)May include surrounding context.

python
wait = max(0, int(reset_ts) - int(time.time())) if reset_ts else 60
            print(f"\n⚠️  GitHub API 请求超限,请等待 {wait} 秒后重试")
            print("   提示:使用 --token 参数传入 GitHub PAT 可将限额提升至 5000次/小时")
            print("   生成 Token:GitHub → Settings → Developer settings → Personal access tokens → 无需勾选任何权限")
            sys.exit(1)

        resp.raise_for_status()

Credential Access

High
Category
Privilege Escalation
Confidence
81% confidence
Finding

Accepting a personal access token via a --token command-line argument can expose the secret to other local users through shell history, process listings, orchestration logs, or agent telemetry. In an agent skill context, this is more dangerous because the framework may record invoked commands, causing unintended credential disclosure beyond the user's terminal session.

Content

Scanner excerpt · scripts/fetch_stars.py (reported line 329)May include surrounding context.

python
epilog=__doc__,
    )
    parser.add_argument("username", help="GitHub 用户名或主页 URL")
    parser.add_argument("--token", default=None, help="GitHub Personal Access Token(可选)")
    parser.add_argument("--output", default=None, help="输出文件路径(默认:<用户名>_github_stars.md)")
    args = parser.parse_args()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to perform network access and write files, but it does not declare any explicit tool scope or permissions boundaries. This weakens least-privilege controls and can allow the skill to be executed with broader capabilities than are necessary, increasing the blast radius if the skill is modified or misused.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description and overview require generating a '标准化中文 Markdown 报告' and following Chinese naming conventions, but they do not offer the user any language choice or opt-in. This is a natural-language locale policy issue because the skill forces a specific language regardless of user preference.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill contains contradictory execution assumptions: it tells the agent to run the script in the Claude environment and deliver the output, but the error handling says the script must run locally because the server has no external network access. This inconsistency can cause unsafe fallback behavior, operator confusion, or ad hoc changes to execution context that bypass intended controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown template is entirely written in Chinese and specifies Chinese field labels such as '中文描述', indicating the generated report is expected to be in a fixed language. The file does not mention any user language preference, opt-in, or region-specific justification, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The docstring states the tool generates a standardized Chinese Markdown report, and later help text and rendering logic consistently assume Chinese output. Because this is a natural-language policy choice applied unconditionally, it can violate locale/language preference requirements when no user opt-in or alternative is provided.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_stars.py (reported line 126)May include surrounding context.

python
page = 1

    while True:
        url = f"https://api.github.com/users/{username}/starred"
        params = {"per_page": 100, "page": page}
        print(f"  📄 第 {page} 页...", end=" ", flush=True)

Static analysis

No suspicious patterns detected.