Back to skill

Security audit

Commit Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This git commit analyzer has a coherent purpose, but its shell script handles numeric inputs unsafely enough to warrant review before use.

Install only from a specific reviewed commit or release, and avoid letting an agent pass untrusted text into the days or hours parameter until the script validates bounded positive integers. Be aware that reports may expose local commit messages in the terminal output.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
analyzer.sh:19
Finding

Unvalidated Numeric Arguments Permit Bash Arithmetic Command Injection

Content
View full analysis
/dev/null || echo "0") local daily_avg=$(echo "scale=1; $total / $days" | bc 2>/dev/null || echo "0") echo "" echo -e "${BOLD}📊 Full Git Analysis (last ${days} days)${NC}" echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━" echo "" echo -e "${BOLD}Overview${NC}" echo " Total commits: $total" echo " Daily average: $daily_avg" echo " Commits/hour: $cph" echo "" echo -e "${BOLD}Daily Breakdown${NC}" for i in $(seq 0 $((days - 1))); do ``` The `waiting` command similarly accepts the same unvalidated parameter for subsequent arithmetic processing: ```bash detect_waiting() { local hours=${PARAM:-48} ``` ### Technical Analysis The second positional argument is accepted without checking that it contains only a bounded positive integer. For the `report` command, this value is assigned to `days` and evaluated inside Bash arithmetic expansions such as: ```bash $((days * 24)) $((days - 1)) ``` Bash arithmetic evaluation can recursively interpret the value of a referenced variable as an arithmetic expression. Specially constructed values may therefore trigger shell expansions, including command substitution in applicable arithmetic expressions, rather than being treated strictly as numeric data. The same input also reaches `seq`, `git log`, `bc`, and date-related operations without validation. Even when a payload does not achieve command execution, malformed or extremely large values can cause ...[truncated 1497 chars]
Remediation
View remediation
&2 exit 2 fi if (( value > maximum )); then echo "Parameter exceeds the permitted maximum of $maximum." >&2 exit 2 fi } ``` Apply command-specific limits before dispatch: ```bash case "$COMMAND" in report|hourly|categories) validate_positive_integer "$PARAM" 365 ;; waiting) validate_positive_integer "$PARAM" 8760 ;; esac ``` Additional hardening should include: 1. Use `local days="$PARAM"` and quote arguments passed to ordinary commands. 2. Reject signs, whitespace, shell metacharacters, variable names, array syntax, and arithmetic operators. 3. Apply conservative upper bounds to prevent oversized loops and expensive Git history scans. 4. Use `printf` for error messages and return a nonzero status on invalid input. 5. Add regression tests containing command substitutions, arithmetic expressions, negative values, empty values, decimals, whitespace, and very large integers. ]]>

T08 · Insecure Dependencies

Warning
Location
README.md:14
Finding

Installation Instructions Use an Unpinned Mutable Upstream Repository

Content
View full analysis
Remediation
View remediation
``` Further supply-chain controls should include: 1. Publish immutable versioned release artifacts. 2. Provide SHA-256 checksums for distributed files or archives. 3. Sign release tags or artifacts and document signature verification. 4. State the exact audited revision in the installation instructions. 5. Recommend reviewing changes before upgrades rather than automatically pulling the latest default branch. 6. Protect the upstream repository with multi-factor authentication, restricted write access, branch protection, and mandatory review. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.