Back to skill

Security audit

GitHub Automation

Security checks for vulnerabilities and agentic risk

Overview

This GitHub automation skill is mostly aligned with its stated purpose, but it disables TLS verification while sending the user's GitHub token, creating a serious token-interception risk.

Do not use this version with a valuable or broad GitHub token. It should be fixed to use normal TLS verification before installation, and users should prefer a fine-grained token limited to the specific repositories and actions needed. Be aware that issue creation publishes data to GitHub without an extra confirmation prompt.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gh_tool.py:24
Finding

GitHub Token Exposure Due to Disabled TLS Certificate Validation

Content
View full analysis

Vulnerability Details

File Location: scripts/gh_tool.py, lines 24–26; the insecure context is used at line 40
Vulnerability Type: Improper TLS certificate and hostname validation
Risk Level: High

Vulnerable Code:

python
ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE

The resulting context is used for authenticated requests:

python
headers = {
    'Authorization': f'token {token}',
    'Accept': 'application/vnd.github.v3+json',
    'User-Agent': 'GitHub-Automation/1.0'
}

req = urllib.request.Request(url, headers=headers, method=method, data=data)

try:
    with urllib.request.urlopen(req, timeout=30, context=ctx) as response:
        return json.loads(response.read().decode('utf-8'))

Technical Analysis

The script explicitly disables both certificate-chain verification and hostname validation. Consequently, it will accept an arbitrary certificate rather than verifying that the remote peer is genuinely api.github.com.

Every API request includes the GITHUB_TOKEN in its Authorization header. Although sending that token to GitHub is necessary for the declared automation features, using an unverified TLS connection makes the credential vulnerable to interception. An active network attacker can impersonate GitHub, receive the authorization header and request content, and return forged API responses.

Attack Path

  1. A user invokes the skill with GITHUB_TOKEN configured.
  2. An attacker obtains an active network interception position, such as control of an untrusted access point, compromised proxy, or manipulated network route.
  3. The attacker intercepts the connection intended for api.github.com and presents an attacker-controlled TLS certificate.
  4. Because hostname and certificate verification are disabled, the script accepts the certificate.
  5. The script transmits the Authorization: token ... header ...[truncated 867 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the assignments to ctx.check_hostname and ctx.verify_mode.
  • Use Python's default verified TLS behavior:
python
ctx = ssl.create_default_context()

with urllib.request.urlopen(req, timeout=30, context=ctx) as response:
    return json.loads(response.read().decode('utf-8'))

Alternatively, omit the explicit context so urlopen uses the platform's trusted certificate configuration.

  • Never add a fallback that retries with certificate verification disabled.
  • Fail closed when certificate-chain or hostname validation fails, and provide a concise error without exposing the token.
  • Use a fine-grained GitHub token restricted to only the required repositories and operations. Avoid broad classic repo scope where narrower permissions suffice.
  • Rotate the configured token if the vulnerable script has been used on an untrusted or potentially intercepted network.
  • Add an automated test using an untrusted certificate to verify that authenticated requests are rejected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tainted flow: 'req' from os.environ.get (line 39, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/gh_tool.py (reported line 42)May include surrounding context.

python
req = urllib.request.Request(url, headers=headers, method=method, data=data)
    
    try:
        with urllib.request.urlopen(req, timeout=30, context=ctx) as response:
            return json.loads(response.read().decode('utf-8'))
    except urllib.error.HTTPError as e:
        return {'error': f'HTTP {e.code}: {e.reason}'}

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is a real security issue because the documented behavior does not fully match the effective behavior, including use of insecure SSL settings that disable certificate and hostname verification. That can enable man-in-the-middle interception of GitHub API traffic and compromise the GITHUB_TOKEN, while undocumented notification access also expands the data exposure beyond what users were told to expect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The tool disables TLS certificate and hostname verification before sending authenticated GitHub API requests. This enables man-in-the-middle interception or spoofing of api.github.com, which can expose the GitHub token and allow tampering with API responses or operations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises code that uses environment variables and network access but does not declare any explicit tool scope or allowed-tools boundaries. In an agent setting, missing scope declarations weakens least-privilege controls and makes it easier for the skill to access sensitive tokens or perform unintended outbound actions without clear policy constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill supports state-changing remote actions such as creating and closing GitHub issues but does not clearly warn users that it will modify repository data. In an agent workflow, this increases the chance of accidental or socially engineered destructive actions because users may interpret the skill as read-only or informational.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs authenticated HTTP requests to the GitHub API using the user's GITHUB_TOKEN, which transmits credentials and potentially repository or notification data over the network. Although the functions have internal docstrings, there is no explicit user-facing warning at the point of use that commands will send authenticated data to GitHub.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes creating issues, checking PR status, listing repos, and managing projects. This code also retrieves the authenticated user's notifications, which is a separate mailbox-style capability not mentioned in the stated scope and not an obvious implementation detail of the listed tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The issue create command causes a state-changing action on GitHub by creating a new issue, but the CLI does not warn the user or request confirmation before performing that write. The command list shows syntax only and does not clearly disclose that invoking this path will modify remote repository data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says the skill can 'manage projects,' but the command dispatcher only supports issue, PR, repo, and notifications operations. No GitHub Projects endpoints or project-related commands are present, so the actual behavior is narrower than the declared description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.