T09 · Insecure Skill Coding Practices
- Location
SKILL.md:26- Finding
Execution of Unverified Repository and Home-Directory Scripts
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 26-42
Vulnerability Type: Unverified local script execution
Risk Level: Highbash scripts/automerge <pr> scripts/massageprs <pr1> <pr2>bash repo_root="$(git rev-parse --show-toplevel 2>/dev/null || pwd)" if [ -x "$repo_root/scripts/ensure-workflow-docs" ]; then "$repo_root/scripts/ensure-workflow-docs" all elif [ -x "$HOME/ai_code/study_peter/scripts/ensure-workflow-docs" ]; then "$HOME/ai_code/study_peter/scripts/ensure-workflow-docs" all else echo "ensure-workflow-docs not found" fiTechnical Analysis
The skill prioritizes executing scripts from the active repository and a hard-coded location under the user's home directory. It checks only whether
ensure-workflow-docsis executable; it does not verify script ownership, integrity, provenance, contents, repository trust, or whether the working tree and checked-out branch are trusted.Repository files are potentially attacker-controlled, particularly when an agent processes pull requests or operates on a branch containing contributed changes. An attacker can place or modify
scripts/automerge,scripts/massageprs, orscripts/ensure-workflow-docsand cause the agent to execute arbitrary commands. The home-directory fallback introduces an additional trust boundary because the selected executable is outside the audited skill package and can be replaced independently.Attack Path
- An attacker adds or modifies one of the preferred scripts in a repository or pull-request branch, or replaces the executable at
$HOME/ai_code/study_peter/scripts/ensure-workflow-docs. - A user asks the agent to process, merge, or batch-handle pull requests.
- Following the skill instructions, the agent selects the repository script before using the explicit GitHub CLI fallback.
- The attacker-controlled script runs with the agent process's operating-syst ...[truncated 952 chars]
- An attacker adds or modifies one of the preferred scripts in a repository or pull-request branch, or replaces the executable at
- Remediation
View remediation
Remediation Suggestions
- Prefer a fixed, reviewable sequence of explicit
ghcommands instead of automatically executing repository-controlled scripts. - Do not execute scripts from a pull-request branch or untrusted working tree. Resolve and verify a trusted base revision before selecting automation code.
- Remove the
$HOME/ai_code/study_peter/scripts/ensure-workflow-docsfallback, or replace it with a centrally managed executable whose path, ownership, permissions, and cryptographic digest are verified. - If repository scripts are necessary, inspect their complete contents and obtain explicit user approval before execution.
- Require trusted ownership, reject group- or world-writable scripts and parent directories, and verify scripts against an approved digest or signed revision.
- Run approved scripts in a restricted environment with minimal filesystem access, sanitized environment variables, no unnecessary credentials, and constrained network access.
- Avoid passing sensitive GitHub credentials to repository-controlled processes. Grant only the repository permissions needed for the requested merge operation.
- Check that the repository is clean and that automation scripts match a trusted default-branch revision before running them.
- Prefer a fixed, reviewable sequence of explicit
