Back to skill

Security audit

peter-pr-ops

Security checks for vulnerabilities and agentic risk

Overview

This skill has a clear PR-automation purpose, but it gives an agent high-impact merge authority and tells it to run unaudited local scripts without enough user control.

Install only if you intend this agent to perform real PR merge operations in trusted repositories. Before use, require an explicit merge confirmation, inspect any scripts/automerge, scripts/massageprs, and ensure-workflow-docs script that would run, and avoid using it on untrusted PR branches or repositories where contributors can modify those scripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:26
Finding

Execution of Unverified Repository and Home-Directory Scripts

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 26-42
Vulnerability Type: Unverified local script execution
Risk Level: High

bash
scripts/automerge <pr>
scripts/massageprs <pr1> <pr2>
bash
repo_root="$(git rev-parse --show-toplevel 2>/dev/null || pwd)"
if [ -x "$repo_root/scripts/ensure-workflow-docs" ]; then
  "$repo_root/scripts/ensure-workflow-docs" all
elif [ -x "$HOME/ai_code/study_peter/scripts/ensure-workflow-docs" ]; then
  "$HOME/ai_code/study_peter/scripts/ensure-workflow-docs" all
else
  echo "ensure-workflow-docs not found"
fi

Technical Analysis

The skill prioritizes executing scripts from the active repository and a hard-coded location under the user's home directory. It checks only whether ensure-workflow-docs is executable; it does not verify script ownership, integrity, provenance, contents, repository trust, or whether the working tree and checked-out branch are trusted.

Repository files are potentially attacker-controlled, particularly when an agent processes pull requests or operates on a branch containing contributed changes. An attacker can place or modify scripts/automerge, scripts/massageprs, or scripts/ensure-workflow-docs and cause the agent to execute arbitrary commands. The home-directory fallback introduces an additional trust boundary because the selected executable is outside the audited skill package and can be replaced independently.

Attack Path

  1. An attacker adds or modifies one of the preferred scripts in a repository or pull-request branch, or replaces the executable at $HOME/ai_code/study_peter/scripts/ensure-workflow-docs.
  2. A user asks the agent to process, merge, or batch-handle pull requests.
  3. Following the skill instructions, the agent selects the repository script before using the explicit GitHub CLI fallback.
  4. The attacker-controlled script runs with the agent process's operating-syst ...[truncated 952 chars]
Remediation
View remediation

Remediation Suggestions

  • Prefer a fixed, reviewable sequence of explicit gh commands instead of automatically executing repository-controlled scripts.
  • Do not execute scripts from a pull-request branch or untrusted working tree. Resolve and verify a trusted base revision before selecting automation code.
  • Remove the $HOME/ai_code/study_peter/scripts/ensure-workflow-docs fallback, or replace it with a centrally managed executable whose path, ownership, permissions, and cryptographic digest are verified.
  • If repository scripts are necessary, inspect their complete contents and obtain explicit user approval before execution.
  • Require trusted ownership, reject group- or world-writable scripts and parent directories, and verify scripts against an approved digest or signed revision.
  • Run approved scripts in a restricted environment with minimal filesystem access, sanitized environment variables, no unnecessary credentials, and constrained network access.
  • Avoid passing sensitive GitHub credentials to repository-controlled processes. Grant only the repository permissions needed for the requested merge operation.
  • Check that the repository is clean and that automation scripts match a trusted default-branch revision before running them.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The applicable-scenario section says the skill applies when the user mentions phrases like “合并这个 PR” and “批量清理 PR”, plus the broader “自动处理评论与 CI”, without defining clearer scope, exclusions, or negative examples. In a markdown skill description, this can cause unintended invocation because these are common request phrasings and the document does not specify when the skill should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to perform high-impact repository operations, including merging PRs and modifying docs/SESSION-BOOTSTRAP.md, without an explicit warning, confirmation boundary, or authorization check. In context, this is dangerous because a broadly invoked automation skill can cause unintended code integration or repository state changes if triggered by an imprecise request or used in the wrong repository/session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The description and operating instructions are presented entirely in Chinese, which implicitly fixes the interaction language without any opt-in or explanation. Under the policy, language constraints should either be user-selectable or clearly justified as region- or audience-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.