Back to skill

Security audit

windows-shell

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent Windows shell guidance, but it recommends running an unpinned external setup script and persistent user-level configuration changes that users should review first.

Install only if you want Windows Git Bash/MSYS2 encoding and shell-routing guidance. Review any persistent environment, shell profile, and global Git changes before applying them, and avoid the one-click external setup command unless you inspect a pinned version of that repository first.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/encoding.md:46
Finding

Execution of an Unpinned External Setup Script

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/encoding.md (reported line 36)May include surrounding context.

le("PYTHONUTF8", "1", "User"); [Environment]::SetEnvironmentVariable("PYTHONIOENCODING", "utf-8", "User")'

2) bash 显示相关变量(登录 shell 用),并让 .bashrc 也加载,覆盖非登录交互 shell

cat >> ~/.bash_profile <<'EOF' export PYTHONUTF8=1 export PYTHONIOENCODING=utf-8 export LANG=en_US.UTF-8 export LESSCHARSET=utf-8 EOF grep -q 'bash_profile' ~/.bashrc 2>/dev/null || echo '[ -f ~/.bash_profile ] && . ~/.bash_profile' >> ~/.bashrc

3) Git 全局配置

git config --global core.quotepath false # 中文文件名正常显示 git config --global core.autocrlf input # 提交 LF,检出保持原样 git config --global i18n.commitEncoding utf-8 # commit 消息 UTF-8 git config --global i18n.logOutputEncoding utf-8 git config --global core.pager "less -R"

text

> 一键配置:在 [skill-factory](https://github.com/Chenmo0414/win-encoding-fix) 仓库里执行 `node bin/cli.js setup-env`

### 规则 1:PowerShell 命令必须加 UTF-8 前缀 + �

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explicitly fixes the user environment to Windows 10/11 with code page GBK/936 and MSYS2/Git Bash, establishing a specific locale assumption in natural language. Under the policy rule, forcing a locale without offering user choice or clearly documenting an opt-in can be a language/locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill content is written as Chinese-only guidance with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/gitbash-pitfalls.md (reported line 57)May include surrounding context.

md
Git Bash 与 Windows 共用 `C:\Users\你\.ssh`,**WSL 用的是独立的 `/root/.ssh`**。在 Windows 配好的 SSH,到 WSL 里等于从零开始。

而且 `/mnt/*` 上的文件在 WSL 眼里权限是 `777`,OpenSSH 会判定 `bad permissions` 直接忽略该密钥。要在 WSL 里用 ssh,密钥必须复制到 ext4 并 `chmod 600`。Git Bash 没有这个问题(它走 Windows ACL,不看 POSIX 权限位)。

### 附:管道会吞掉退出码

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown instructs users to set LANG=en_US.UTF-8 as part of the recommended persistent configuration. This is a natural-language locale policy constraint that forces English locale behavior rather than offering a choice or explaining why English is required for this skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.