T09 · Insecure Skill Coding Practices
- Location
scripts/collect_commit_context.sh:222- Finding
Authenticated Git Remote URL Disclosed in Generated Context
- Content
View full analysis
/dev/null || echo unknown)" remote_url="$(git -C "$repo" remote get-url origin 2>/dev/null || echo none)" echo "=== REPOSITORY CONTEXT ===" echo "repo_root: $repo_root" echo "branch: $current_branch" echo "remote: $remote_url" ``` ### Technical Analysis The script retrieves the complete URL of the Git `origin` remote and places it directly into generated review context. Git remote URLs can contain URI user information, including usernames, access tokens, or passwords, such as: ```text https://username:token@example.com/private/repository.git ``` The code performs no redaction before printing the value. Consequently, embedded credentials and private repository information can be exposed to the AI agent, command logs, captured output, audit systems, or users who can view the generated context. The remote URL is not necessary to inspect the contents of a local commit, making this disclosure avoidable. ### Attack Path 1. A repository is configured with credentials embedded in its `origin` URL. 2. A user invokes the skill to inspect a commit in that repository. 3. The script executes `git remote get-url origin`. 4. The complete authenticated URL is printed as the `remote` field. 5. The credential becomes available in generated agent context, logs, or other downstream output. 6. Anyone with access to that output may extract the credential and use it according to its existing permissions and validity. ### Impact Assessment This issue does not directly grant elevated local privileges. Its impact depends on the credential embedded in the remote URL. A disclosed token or password could permit unauthor ...[truncated 320 chars]- Remediation
View remediation
