T09 · Insecure Skill Coding Practices
- Location
SKILL.md:45- Finding
Unrestricted Workspace Staging and Automatic Remote Push
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 45-54
Vulnerability Type: Unrestricted staging and unconfirmed remote publication
Risk Level: HighVulnerable Code
bash cd <workspace> git add -A git status git commit -m "wrap-up: YYYY-MM-DD session summary" git pushtext Notes: - The wrap-up `git push` is **automatic** (no confirmation prompt).Technical Analysis
The skill uses
git add -A, which stages every modified, deleted, and untracked file in the workspace. It does not restrict staging to the daily log, long-term memory, or PARA files that the skill is intended to update.The resulting commit is then pushed automatically to the repository's configured remote without obtaining user confirmation. Although
git statusis executed, the instructions do not require the agent or user to review its output, inspect the staged diff, scan for secrets, verify the destination remote, or approve publication.This violates least-privilege principles and creates a data-exfiltration path through ordinary Git operations. Sensitive or unrelated workspace content can be included even when it was not generated by the wrap-up process.
Attack Path
- A workspace contains a sensitive, unrelated, or attacker-planted file, such as an environment file, API credential, private note, proprietary source file, or generated artifact.
- The file is modified or untracked when the user invokes the session wrap-up skill.
- The skill executes
git add -A, staging the sensitive file along with its intended memory updates. - The skill creates a commit containing all staged changes.
- The skill executes
git pushautomatically, without presenting the staged diff or requesting approval. - The sensitive content is published to the configured Git remote and may become accessible to repository collaborators, administrators, automated systems, or the public, depending on reposit ...[truncated 659 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
git add -Awith an explicit allowlist of files created or modified by the wrap-up protocol, for example:bash git add -- "memory/YYYY-MM-DD.md" "MEMORY.md" "notes/areas/open-loops.md" - Track which files the skill actually changed and stage only those paths. Do not stage unrelated pre-existing modifications.
- Review
git diff --cached --name-statusandgit diff --cachedbefore committing. - Run secret detection against the staged content and abort if credentials, private keys, tokens, environment files, or other sensitive material are found.
- Display the exact staged files, target branch, and configured remote URL to the user.
- Require explicit user confirmation before both committing and pushing. A failed or declined confirmation must leave the changes unpushed.
- Avoid pushing directly to protected or shared branches; use a dedicated branch where appropriate.
- Preserve unrelated workspace changes without staging, reverting, deleting, or otherwise modifying them.
- Replace
