Back to skill

Security audit

GitHub Actions Failure Hour Audit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, disclosed GitHub Actions report tool that reads workflow-run JSON files and summarizes failure timing without hidden network, write, persistence, or credential behavior.

Install this if you want a local report over GitHub Actions run exports. Keep RUN_GLOB pointed at the intended artifact directory because the script will read every matching JSON file, and review JSON output before sharing it since repository, workflow, branch, run IDs, and URLs may appear in the report.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares executable behavior that reads local files via a shell script and globbed JSON inputs, but it does not define any explicit tool scope such as permissions or allowed-tools. Without a declared scope, an agent framework may grant broader-than-necessary file access, increasing the chance of unintended data exposure if the script is invoked in a sensitive workspace.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.