Back to skill

Security audit

commit-tidy

Security checks for vulnerabilities and agentic risk

Overview

This commit-management skill is broadly purpose-aligned, but it includes under-disclosed agent hooks, persistent hook guidance, and broad GitHub/agent-config access that users should review before installing.

Review this skill before installing if you work in shared repositories or use Claude-style local configuration. Keep commit and push execution under explicit confirmation, do not enable the PreToolUse/PostToolUse hooks unless you intentionally want persistent agent behavior, and treat repository `.claude/rules` content as untrusted unless your team owns it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says this skill helps analyze staged/committed changes and recommend strategies such as split, squash, amend, staging discipline, security scanning, and commit-message guidance. The supplied code does not implement any of those review/recommendation functions. Instead, it acts as an automated trigger hook: it inspects JSON input for Bash tool calls, detects whether a real git commit command was run successfully, parses the commit hash from stdout, and prints instructions to invoke a code-reviewer subagent. This is a materially different primary purpose and trigger model than the declared one. Although both relate broadly to commits/review, the actual code is specifically a post-commit automation trigger, which is undeclared.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
88% confidence
Finding

The skill instructs the agent to enumerate and read files under .claude/rules/, an agent configuration area that may contain sensitive instructions, local policies, credentials, or operational context unrelated to the user's request. Accessing agent/config directories broadens the trust boundary and can expose hidden prompt material or secrets to downstream processing, especially when done automatically as a hard-stop prerequisite.

Content

Scanner excerpt · SKILL.md (reported line 259)May include surrounding context.

bash
REPO_ROOT="$(git rev-parse --show-toplevel)"
find "$REPO_ROOT/.claude/rules/" -name '*.md' 2>/dev/null

If the find returns one or more files, grep them for commit-type semantics (recursive to match the find scope above):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · interactive-amend.md (reported line 85)May include surrounding context.

Per git.md: force push requires CI status check (HARD STOP)

gh run list --branch --limit 5 --json status,conclusion

Only force push after CI is clean or no runs exist

git push --force-with-lease origin

text

### Step 4. Cleanup

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
94% confidence
Finding

The skill instructs the agent to enumerate and read .claude/rules/*.md from the repository, which is a local agent-configuration area that may contain sensitive instructions, secrets, or trust-boundary-crossing content not necessary for the user's immediate request. Treating those files as authoritative input increases the chance of prompt injection, secret exposure, or unintended execution paths driven by repository-controlled config.

Content

Scanner excerpt · message-discipline.md (reported line 191)May include surrounding context.

md
### Self-check (every time before drafting a commit message)

1. `git rev-parse --show-toplevel` → `<repo>`
2. `find <repo>/.claude/rules/ -name '*.md' 2>/dev/null` — does the workspace ship any local rules?
3. If 1+ files exist, grep them for commit-type / version semantics: `grep -liE 'commit type|conventional commit|version bump|feat|fix|topic' <repo>/.claude/rules/*.md`
4. Read each match. If a local rule defines its own mapping (e.g., "new topic = feat, in-place edit of existing topic = fix"), **the local rule wins**. Re-classify the staged diff under the local rule before composing the subject
5. If no local rule applies, fall back to the global defaults below ("Verb selection" + "Tag selection criteria")

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
93% confidence
Finding

This repeated instruction reinforces mandatory access to .claude/rules/ and elevates repository-local rule files above the skill's own defaults, effectively allowing repo-controlled content to steer agent behavior. That creates a strong prompt-injection and trust-boundary issue because an attacker who can modify those files can influence the agent's decisions and possibly expose internal policy or sensitive context.

Content

Scanner excerpt · message-discipline.md (reported line 200)May include surrounding context.

md
| # | Don't | Do |
|---|-------|-----|
| 1 | Apply the global "`.md` behavior-change addition ⇒ `feat:`" rule without checking the working tree's `.claude/rules/` | Run the self-check (`find <repo>/.claude/rules/ -name '*.md'`) first. If a local mapping exists, defer to it |
| 2 | Treat the local rule as "informational only" and stick with the global default | Local rule overrides the global default. The override is the source of truth for the commit type, not a suggestion |
| 3 | Add an HARD STOP / Don't-Do row to an existing topic and prefix `feat(skill-X):` autonomously | Inspect the diff for "new topic file / new SKILL.md Topics-table row." None? → look for the local rule's classification (`fix` / `chore` / etc.). Many → `feat:` only when a topic file actually appears |
| 4 | Self-check the local rule once per session and assume it still holds for later commits | The diff scope changes per commit. The classification is per-commit, not per-session |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · security-scan.md (reported line 75)May include surrounding context.

md
## Escalation

Cumulative violations → install the PreToolUse:Bash hook `block-secret-in-commit.sh` (registered via `~/.claude/settings.json`). The hook runs the same 4 greps against `git diff --cached` whenever a `git commit` invocation is detected and rejects the commit if any grep matches.

## Related topics

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · soft-reset-amend.md (reported line 125)May include surrounding context.

Per git.md: force push requires CI status check (HARD STOP)

gh run list --branch $(git branch --show-current) --limit 5 --json status,conclusion

Only force push after CI is clean or no runs exist

git push --force-with-lease origin $(git branch --show-current)

text

## Example

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Enforcing English commit messages without opt-in is not a classic security flaw, but it is a policy overreach that can cause integrity and workflow issues by rewriting or constraining user intent. In multilingual or regulated environments, forced language normalization may degrade accuracy, exclude users, or pressure disclosure in a nonpreferred language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The topic description frames English enforcement as a mandatory rule, again exceeding what is necessary for commit hygiene and potentially overriding repository or user policy. While not directly enabling compromise, mandatory language restrictions can interfere with correct communication and make the skill less trustworthy by imposing non-security policy without consent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 211)May include surrounding context.

Provide specific recommendations. Every recommended commit includes a body by default (see message-discipline.md "Default commit message structure"). The body is free-form — it does not have to enumerate per-file changes.

Mandatory Interactive Ask Gate (HARD STOP): Autonomous commit execution or git push without user confirmation is STRICTLY FORBIDDEN. After presenting the split/squash recommendation, you MUST present the split options to the user via AskUserQuestion to obtain explicit approval before executing any git commit or git push. Even when git pull --rebase is required or executed, automatically running git push afterwards is strictly forbidden without a new AskUserQuestion confirmation.

text
## Analysis Results

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This section expands a local commit-tidying skill into networked GitHub PR inspection via gh pr and gh api, which can disclose repository metadata externally and exceeds least-privilege expectations for a local hygiene tool. The risk is contextual rather than overtly malicious: users may invoke the skill expecting only local git analysis, but the workflow requires authenticated remote queries and may operate on the wrong repo/account context.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · conflict-commit-review.md (reported line 145)May include surrounding context.

md
| 4 | Accept one side of the file wholesale because it passes the tests | Passing is necessary, not sufficient — the failing side may carry coverage the passing side dropped. Compare what each side *has*, then merge |
| 5 | Split every hunk into its own ask because "chunk by chunk" was requested | Group by trade-off (Step 2). Chunk-level review means no real decision gets bundled away, not that mechanical hunks each get a turn |
| 6 | Push the branch and handle the conflict commit afterwards | The commit is inside the push range; once it is on a remote, fixing it becomes a force-push decision affecting everyone who fetched it |
| 7 | Commit the reviewed resolution without checking who else owns those files | If the affected files were already modified in the checkout before this work began, the commit carries someone else's in-flight change — see [staging-discipline.md](./staging-discipline.md) |

## Self-check (before any squash / reword / push touching the range)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · message-discipline.md (reported line 200)May include surrounding context.

md
| 4 | Accept one side of the file wholesale because it passes the tests | Passing is necessary, not sufficient — the failing side may carry coverage the passing side dropped. Compare what each side *has*, then merge |
| 5 | Split every hunk into its own ask because "chunk by chunk" was requested | Group by trade-off (Step 2). Chunk-level review means no real decision gets bundled away, not that mechanical hunks each get a turn |
| 6 | Push the branch and handle the conflict commit afterwards | The commit is inside the push range; once it is on a remote, fixing it becomes a force-push decision affecting everyone who fetched it |
| 7 | Commit the reviewed resolution without checking who else owns those files | If the affected files were already modified in the checkout before this work began, the commit carries someone else's in-flight change — see [staging-discipline.md](./staging-discipline.md) |

## Self-check (before any squash / reword / push touching the range)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · interactive-amend.md (reported line 21)May include surrounding context.

Step 0. Worktree Preparation

bash
# Acquire worktree via /git-repo worktree (reuse inactive or create new)
# The worktree branch will be used as the working area

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs history rewriting followed by git push --force-with-lease but does not explicitly warn about coordination risks for collaborators or the effect on shared remote history. Even with a CI gate and --force-with-lease, users may disrupt teammates' branches, invalidate reviews, or overwrite expected remote state if they do not confirm the branch is safe to rewrite.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that if a repository is PUBLIC, English is mandatory for commit messages. This is a language-policy constraint applied by default rather than offered as a user choice, which matches the rule's language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill directs the agent toward amend-and-force-push behavior as the preferred path once a user has indicated amend intent, and frames force-with-lease as routine without requiring a fresh, explicit warning at the moment of execution. This can lead an agent to perform history-rewriting operations that may disrupt collaborators, invalidate review context, or overwrite remote state if the situation is misunderstood.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The phrase "commit message PUBLIC English enforcement" describes a language requirement in the skill documentation. This is a natural-language locale policy constraint, and the file does not indicate user opt-in or a clearly justified region-specific/compliance reason for forcing English.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill imposes a language-specific policy by asserting that 'workspace-local Korean rules never belong in a PUBLIC repo commit' without requiring repository policy or user opt-in. That can cause the agent to suppress or block legitimate commits based on content language rather than objective security or repository rules, creating an integrity/governance risk and potential discriminatory behavior.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
73% confidence
Finding

The skill directs the agent to reason about and act around 'another task in progress' and to leave that work alone or move to a new worktree, which relies on persistent cross-task/session state. In agent contexts, this can lead to unintended retention or inference of prior task context and influence current actions based on unrelated session activity.

Content

Scanner excerpt · staging-discipline.md (reported line 98)May include surrounding context.

git status (change list) ├─ Only my single change, branch = PR/feature → commit directly ├─ Mine + other-task, branch = main/master/develop → /git-repo worktree split mandatory ├─ Only mine, branch = main/master/develop → present both "create PR branch" and "split into worktree + create PR branch" └─ Another task in progress on a PR branch → leave it alone. Return to main and create a new worktree

text

Static analysis

No suspicious patterns detected.