Back to skill

Security audit

gitlab-commit-report

Security checks for vulnerabilities and agentic risk

Overview

This skill behaves like a GitLab commit report tool and stores fetched activity locally, but users should install it carefully because its dependencies are not locked.

Before installing, review or pin the dependencies and use a lockfile, especially @bondli-skills/shared because it provides the browser connection helper. Run the skill only against the intended GitLab host and group, and remember that commit metadata, author names, repository names, and commit messages will be stored locally until you delete them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
package.json:13
Finding

Mutable Third-Party Dependencies Installed Without a Lockfile

Content
View full analysis

Vulnerability Details

File Location: package.json:13-18 and README.md:34-37
Vulnerability Type: Supply-chain exposure through mutable dependency versions
Risk Level: Medium

The project instructs users to install dependencies while specifying all direct dependencies with mutable caret version ranges. No lockfile, integrity hashes, vendored dependency sources, or other reproducible-installation controls were included in the audited artifact.

Relevant installation instruction (README.md:34-37):

bash
# Install dependencies
pnpm install

Complete dependency declaration (package.json:13-18):

json
"dependencies": {
  "@bondli-skills/shared": "^1.0.0",
  "axios": "^1.6.0",
  "puppeteer": "^22.0.0",
  "puppeteer-core": "^22.15.0"
}

Technical Analysis

Caret ranges permit the package manager to resolve newer compatible releases than those originally reviewed. Because the repository contains no lockfile, separate installations can resolve to different package versions and transitive dependency trees.

Package installation can also invoke dependency lifecycle scripts. If an allowed dependency version or one of its transitive dependencies is compromised, a malicious release can execute code during installation or introduce malicious runtime behavior. The scoped package @bondli-skills/shared could not be audited from the supplied artifact, and its provenance and effective installed contents are therefore unknown.

This risk is particularly relevant because the documented skill is intended to interact with an existing authenticated Chrome session for a corporate GitLab instance. A malicious dependency running in that context could attempt to access local files, environment variables, browser debugging interfaces, or authenticated browser data available to the process.

Attack Path

  1. An attacker compromises a declared dependency, its publisher account, or a transitive d ...[truncated 1237 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace caret ranges with reviewed, exact dependency versions.
  2. Generate and commit pnpm-lock.yaml so direct and transitive dependency resolution is reproducible and includes package integrity information.
  3. Review the ownership, publication history, source, and packaged contents of @bondli-skills/shared before trusting it in a process that can access an authenticated browser session.
  4. Use continuous dependency scanning and monitor dependencies for compromised releases and known vulnerabilities.
  5. In automated or high-trust environments, install with the frozen-lockfile option so dependency drift causes installation to fail.
  6. Disable dependency lifecycle scripts where operationally feasible, or explicitly review every package that requires such scripts before permitting execution.
  7. Run installation and collection under a dedicated, least-privileged account with restricted filesystem and network access.
  8. Avoid exposing the browser debugging interface beyond the local machine, and ensure the process can connect only to the intended browser session and GitLab host.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a specific functional skill related to GitLab event collection and report generation. However, the provided code chunk contains only an empty TypeScript declaration file (export {};) with no executable logic, integrations, triggers, or data handling. This is a material mismatch because the actual code does not implement the stated primary purpose at all.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill description is written in Chinese and does not indicate that the user can choose another language or locale. Under the policy rules, a skill that effectively mandates a specific language without opt-in is a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes behavior requiring network access and likely environment/file access, but it does not declare any explicit tool scope or permissions. This weakens security boundaries and transparency, making it easier for an agent runtime to grant broader capabilities than users expect when interacting with GitLab and local stored data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Multiple comments and console messages are written only in Chinese, including operational and error output. This creates a language-policy issue because the skill effectively forces a specific language for user-visible interaction without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file emits all user-facing report content and console messages in Chinese, including headings and status output. This enforces a specific language/locale without any opt-in, selection mechanism, or justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a GitLab group push events collector and daily commit report generator, which would ordinarily require GitLab API access and report generation. Declaring both puppeteer and puppeteer-core suggests headless browser automation capability, which is not an obvious or documented requirement for collecting push events or generating commit reports.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill collects GitLab activity data and writes raw events and generated reports to disk, but it does not clearly warn users about persistent local storage of potentially sensitive engineering metadata. This can lead to unintended retention of commit messages, repository names, and contributor activity, increasing privacy and data handling risk on shared systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

At L29 the code tells the user to fill in their GitLab information, and at L32 it reads that config file, which likely contains sensitive connection details. While the file-missing path mentions editing the config, there is no direct user-facing warning in the main execution flow that the skill will access stored account data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file prints user-facing usage and error text exclusively in Chinese, which imposes a specific language on users without any opt-in or alternative. Under the policy for natural-language violations, this is a locale/language restriction that should be either optional or explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The login error output is written only in Chinese, which imposes a specific language on users without any opt-in or alternative locale handling. This matches the language/locale policy violation category because the file does not provide a user choice or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The progress log message is hard-coded in Chinese, requiring a specific language for normal operation feedback. There is no indication that users can select their language or that the tool is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This thrown error message is emitted only in Chinese, and similar Chinese-only status messages appear later in the file. Without opt-in, fallback, or a documented regional constraint, this constitutes a language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The thrown error message at L18 is hard-coded in Chinese, which imposes a specific language on users without any indication of language choice or locale justification. This is a natural-language policy concern because the skill does not appear to offer opt-in or fallback behavior for other locales.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The thrown error message at L31 is hard-coded in Chinese, which forces a specific language for users encountering parse failures. No language choice, fallback, or documented region-specific constraint is visible in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The console warning at L43 is a user-visible string hard-coded in Chinese, creating a language-specific experience without opt-in or documented justification. Under the locale policy, user-facing text should not force a specific language unless clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

Line L50 writes accumulated event data to a JSON file under the user's home directory, but this file provides no confirmation prompt, print/log statement about the write, or comment/docstring explaining that persistent local storage occurs. Because this is a code file and the operation affects user/system data on disk, it should include some visible disclosure unless covered elsewhere by the skill description.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

Using a caret range for @bondli-skills/shared allows newer dependency releases to be installed without explicit review, increasing supply-chain risk and making builds non-reproducible. If an upstream release is compromised or introduces insecure behavior, this package could silently consume it.

Content

Scanner excerpt · package.json (reported line 15)May include surrounding context.

json
"config.example.json"
  ],
  "dependencies": {
    "@bondli-skills/shared": "^1.0.0",
    "axios": "^1.6.0",
    "puppeteer": "^22.0.0",
    "puppeteer-core": "^22.15.0"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

Using a non-exact axios version permits automatic adoption of newer releases within the range, which weakens reproducibility and can expose consumers to supply-chain or regression risk. Because axios is network-facing and commonly used for HTTP requests, insecure or compromised updates could directly affect data handling and outbound requests.

Content

Scanner excerpt · package.json (reported line 16)May include surrounding context.

json
],
  "dependencies": {
    "@bondli-skills/shared": "^1.0.0",
    "axios": "^1.6.0",
    "puppeteer": "^22.0.0",
    "puppeteer-core": "^22.15.0"
  },

Unverifiable Dependency: axios has 16 known advisory(ies) (CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Using a caret range for puppeteer allows unreviewed browser-automation code changes to enter the build, increasing supply-chain and execution risk. Because puppeteer can drive a full browser, compromised or vulnerable updates can have greater security consequences than many ordinary libraries.

Content

Scanner excerpt · package.json (reported line 17)May include surrounding context.

json
"dependencies": {
    "@bondli-skills/shared": "^1.0.0",
    "axios": "^1.6.0",
    "puppeteer": "^22.0.0",
    "puppeteer-core": "^22.15.0"
  },
  "license": "MIT"

Unverifiable Dependency: puppeteer has 1 known advisory(ies) (CVE-2019-5786 (Use-After-Free in puppeteer)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Using a non-exact version for puppeteer-core creates the same reproducibility and supply-chain exposure as other floating dependencies, with elevated concern because it enables direct control of browser instances. Unexpected upstream changes can alter security-sensitive behavior or introduce exploitable flaws into an automation-capable package.

Content

Scanner excerpt · package.json (reported line 18)May include surrounding context.

json
"@bondli-skills/shared": "^1.0.0",
    "axios": "^1.6.0",
    "puppeteer": "^22.0.0",
    "puppeteer-core": "^22.15.0"
  },
  "license": "MIT"
}

Static analysis

No suspicious patterns detected.