Back to skill

Security audit

github-flow

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent GitHub workflow skill, but it grants broad GitHub authority and token-handling guidance that users should review carefully before installing.

Install only if you want an opinionated, multi-account GitHub automation workflow. Review the auth-scope and identity-auth topics first, confirm you are comfortable with broad gh scopes and GH_TOKEN injection, and avoid using it in repos where automatic language rules or GitHub state changes would be inappropriate.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (68)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents the skill as GitHub workflow guidance, but the detected behavior includes hidden enforcement and hook-style gating of user/tool payloads, local config reads, and debug logging. This mismatch is dangerous because users and security reviewers cannot accurately assess what the skill will do, especially if it can block tasks, inspect local state, or emit logs without being transparently declared. The combination of policy enforcement and local data access meaningfully expands the attack surface beyond the advertised purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
| auth-scope | gh CLI priority + account mapping + batch scope refresh + org-repo 404 checklist | [auth-scope.md](./auth-scope.md) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
uth scope refresh + GH_TOKEN env fallback for org repo 404 | [identity-auth.md](./identity-auth.md) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
| merge | CI success and AI review check then merge with commit cleanup, including pre-merge blockedBy verification | [merge.md](./merge.md) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
ly registered in any hook config**, so nothing enforces it at runtime | [pr.md](./pr.md) |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · identity-auth.md (reported line 27)May include surrounding context.

md
### IDE Subshell GITHUB_TOKEN override rule (HARD STOP)

In IDE subshell environments (e.g. Antigravity), a dummy or environment-injected `GITHUB_TOKEN` (such as `github_pat_antigravitydummytoken`) may exist in environment variables. `gh` CLI prioritizes `GITHUB_TOKEN` over stored keyring accounts, causing 401 Bad Credentials errors.
- **Rule**: When executing `gh` CLI commands in subshells where `GITHUB_TOKEN` is present, always use `env -u GITHUB_TOKEN gh ...` (or unset `GITHUB_TOKEN` before calling `gh`) so `gh` uses stored keyring credentials.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · identity-auth.md (reported line 28)May include surrounding context.

md
### IDE Subshell GITHUB_TOKEN override rule (HARD STOP)

In IDE subshell environments (e.g. Antigravity), a dummy or environment-injected `GITHUB_TOKEN` (such as `github_pat_antigravitydummytoken`) may exist in environment variables. `gh` CLI prioritizes `GITHUB_TOKEN` over stored keyring accounts, causing 401 Bad Credentials errors.
- **Rule**: When executing `gh` CLI commands in subshells where `GITHUB_TOKEN` is present, always use `env -u GITHUB_TOKEN gh ...` (or unset `GITHUB_TOKEN` before calling `gh`) so `gh` uses stored keyring credentials.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · plan-to-issue.md (reported line 76)May include surrounding context.

echo "$BODY" | grep -P '\p{Hangul}' && echo "BLOCKED: Hangul detected" || echo "OK: English only"

text
Run this for both `--title` and `--body` before posting.
6. **Ralph autonomous mode applies same rule** — no exception for autonomous loops; this rule overrides any `--no-confirm` or speed pressure.

### Step 5.1: Match Repository Language Convention for Private Repos

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · sanitize.md (reported line 126)May include surrounding context.

echo "$BODY" | grep -P '\p{Hangul}' && echo "BLOCKED: Hangul detected" || echo "OK: English only"

text
Run this for both `--title` and `--body` before posting.
6. **Ralph autonomous mode applies same rule** — no exception for autonomous loops; this rule overrides any `--no-confirm` or speed pressure.

### Step 5.1: Match Repository Language Convention for Private Repos

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Lines L79-L90 define a mandatory language policy based on repository visibility: private repos default to Korean and public repos require English, with English for private repos forbidden unless explicitly requested. This is a natural-language locale policy that forces language choice rather than offering the user a choice or requiring opt-in.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · push-guards.md (reported line 37)May include surrounding context.

md
## When a user-specified command fails — pick the alternative via AskUserQuestion

**When a Git command the user explicitly named fails, stop and AskUserQuestion.** Forbid autonomous selection of "a different command that produces the same effect", especially escalation to a forbidden command like `git reset --hard`.

| # | Don't | Do |
|---|-------|-----|

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · push-guards.md (reported line 41)May include surrounding context.

md
## When a user-specified command fails — pick the alternative via AskUserQuestion

**When a Git command the user explicitly named fails, stop and AskUserQuestion.** Forbid autonomous selection of "a different command that produces the same effect", especially escalation to a forbidden command like `git reset --hard`.

| # | Don't | Do |
|---|-------|-----|

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · push-guards.md (reported line 50)May include surrounding context.

md
## Mixed-result push output — per-ref evidence before continuing (HARD STOP)

A push can partially succeed: some refs update while others are `! [rejected]` and git still exits with a command-level `error:`. This clause applies to ANY push output the assistant consumes — assistant-run OR **user-run** (`!` bash-input). Root cause to check first: a refspec-less push (`git push --force-with-lease` with no `origin <branch>`, e.g. a line-wrapped command) under `push.default=matching` attempts EVERY matching branch.

1. **Per-ref evidence table is mandatory** — for each ref in the output: updated/rejected + `git ls-remote origin <ref>` confirmation. Never compress to "the intended ref worked; the rest is noise".
2. **A rejected force-push against a shared/accumulation branch is a near-miss, not noise** — it was saved only by `--force-with-lease` stale-info protection. Flag it explicitly and diagnose why the push targeted that ref at all.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · push-guards.md (reported line 75)May include surrounding context.

md
## Force-push CI status check (HARD STOP)

**Before `git push --force` / `--force-with-lease`, check the current branch's in-progress / latest CI status.** Force-push cancels any in-progress run on the GitHub side and overwrites origin with the failed change.

### Procedure

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

These instructions impose a default language policy for private-repo issues, PRs, comments, and commit messages: Korean unless an exception applies. This is a natural-language policy violation because it forces a specific locale by default rather than offering a user choice or requiring explicit opt-in.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · sanitize.md (reported line 202)May include surrounding context.

bash
# 1. Local workspace paths (inaccessible to others)
grep -E '<workspace-name>/\.claude/|<repo-name>/\.claude/rules/|~/\.claude/skills/|~/\.agents/|\.ralph/|\.omc/' <body>

# 2. Internal RFC1918 IP / hosts
grep -E '10\.[0-9]+\.[0-9]+\.[0-9]+|192\.168\.|172\.(1[6-9]|2[0-9]|3[01])\.|<internal-host-prefix>' <body>

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares dependencies and discusses environment-based auth behavior such as GH_TOKEN fallback, but it does not declare an explicit tool/permission scope. That makes the runtime trust boundary unclear and can allow broader-than-expected access to environment data or tool capabilities when the skill is invoked. In a workflow that interacts with GitHub authentication and publishing, undeclared scope increases the risk of accidental token use or data exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description explicitly includes "PUBLIC English enforcement," which is a natural-language policy constraint. Because the file does not offer a language choice or justify the restriction as a documented region-specific requirement, this appears to force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill discusses creating issues, PRs, comments, reviews, and upstream issues on public or external repositories, but it does not clearly disclose that repository content may be transmitted to GitHub or other third-party services. This can cause users to share internal implementation details, code, or metadata externally without informed consent, especially because the skill is framed as workflow automation rather than data egress.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The topic table says the commit-message-discipline topic includes "PUBLIC repo English enforcement." This is a direct statement of forced language behavior and there is no nearby indication that users may opt in, opt out, or select another language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatically applying the skill whenever the remote contains github.com is overly broad and can trigger the workflow on arbitrary GitHub-hosted repositories, including sensitive or unrelated ones. Because this skill covers publishing, auth handling, sanitization, and merge/push workflow behavior, broad activation raises the chance of unintended external actions or policy enforcement in the wrong repository context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The merge command uses --delete-branch, which is a destructive action that removes the source branch after merge, but the procedure does not explicitly call out that this deletion will occur or require confirmation that the branch is safe to remove. In an automation-oriented skill, that omission increases the chance of unintended branch loss, especially if the branch contains unmerged work, is shared, or the merge target/PR was misidentified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly recommends extracting a GitHub token and injecting it through GH_TOKEN, but it does not pair that guidance with clear handling constraints such as avoiding logging, persisting, echoing, or storing the token in reusable files. In an automation skill, this omission is dangerous because users may copy the pattern into scripts, shell history, CI logs, or shared environments, causing credential exposure and subsequent repository compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section goes beyond one-off token use and recommends reusing a token across script files, while focusing mainly on bypassing a secret-echo guard rather than minimizing secret exposure. That combination increases the chance of unsafe scripting patterns, accidental persistence, guard evasion, and leakage through files, process inspection, debugging output, or future edits to the script.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill hard-codes a language policy based on repository visibility and defaults PRIVATE repositories to Korean without checking user preference. This can override user intent, introduce unauthorized content transformations, and create operational or compliance issues when contributors expect a different language or when automation should preserve user-specified wording.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.