Back to skill

Security audit

github-repo

Security checks for vulnerabilities and agentic risk

Overview

This skill helps configure and verify GitHub repositories, and its repository changes are disclosed, user-directed, and aligned with that purpose.

Before installing, expect this skill to read repository state, create or edit GitHub configuration files, and optionally update branch protection if you choose that action. Review generated templates and language choices before accepting changes, especially for multilingual projects or repositories with existing governance rules.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill directs the agent to generate content in English for open-source repositories based solely on repository visibility, without explicit user preference or consent. This can cause unintended language changes in user-facing repository materials, leading to accessibility, localization, and governance issues in multilingual projects.

Static analysis

No suspicious patterns detected.