Back to skill

Security audit

Rails CI Fixer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Rails CI repair workflow that uses GitHub and local test commands in a purpose-aligned way, with human approval required before commits and merges.

Install this only if you are comfortable letting an agent run Rails tests and RuboCop in repositories you own and trust, and give GH_TOKEN only repo-specific contents:write and actions:read permissions. Review diffs before approving commits, keep branch protection enabled, and do not use it on untrusted third-party code.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security.md (reported line 26)May include surrounding context.

md
## GH_TOKEN Scoping

Use a **fine-grained personal access token** scoped to the specific repo:
- Grant: `contents: write` (push to feature branches), `actions: read` (view CI logs)
- Do NOT grant org-wide or admin permissions
- Set an expiration date and rotate after use

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include very common developer language such as 'fix CI', 'CI is failing', 'watch the PR', and 'the build is broken', which can cause the skill to activate in routine conversation without a deliberate request. Because this skill pulls CI logs, runs repository code locally, and may push changes to a feature branch after human approval, accidental invocation can expose the agent to untrusted code execution and unintended repository modifications.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/common-failures.md (reported line 90)May include surrounding context.

  • Fix: Add to CI workflow:
    yaml
    - name: Install system dependencies
      run: sudo apt-get install -y libvips-dev
    

CI workflow file location

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file presents inconsistent safety guarantees: it says the skill pauses for human approval before committing, yet also describes automatic commits/pushes to a feature branch. In a tool that executes repository code and has write access to GitHub, ambiguous approval/commit semantics can mislead operators into granting trust or tokens under false assumptions, increasing the chance of unintended code changes being pushed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
65% confidence
Finding

L33 asserts a strict policy around what is and is not committed, but the surrounding documentation elsewhere in the file describes the skill as making commits automatically. Given the manifest's requirement to pause before committing, this creates inconsistent intent documentation about when and under whose approval commits occur. The contradiction is documentation-level rather than a code-level implementation detail.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.