Back to skill

Security audit

Github Ops

Security checks for vulnerabilities and agentic risk

Overview

This is a GitHub upload guide, but it tells agents to push broad local changes and gives incomplete advice for accidentally published secrets.

Install only if you are comfortable with an agent guiding Git commands that can publish local files to GitHub. Before following it, confirm the repository is private or intended to be public, review staged files with git status and git diff --cached, scan for secrets or private data, and treat any pushed secret as compromised by rotating it and cleaning repository history.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:129
Finding

Published Credentials Remain Exposed in Git History After Incomplete Removal

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 129–135
Vulnerability Type: Incomplete remediation of secrets committed to a Git repository
Risk Level: High

Complete vulnerable excerpt, translated into English from the source documentation:

markdown
#### Committed Files That Should Not Have Been Committed

- **Symptom:** A password file or large dependency library was accidentally uploaded to the repository.
- **Solution:**
    1. Immediately add the file path to `.gitignore`.
    2. Use `git rm --cached <file-name>` to remove it from Git tracking.
    3. Commit and push the change: `git commit -m "chore: remove sensitive file"` and `git push`.

Technical Analysis

The documented remediation removes the sensitive file only from the repository's current tree. The git rm --cached command followed by a normal commit does not remove the file or its contents from earlier commits. Anyone with access to the repository history may therefore retrieve the exposed password, API key, token, or other secret.

Adding the path to .gitignore prevents accidental staging in future commits, but it does not protect a secret that has already been committed or pushed. The instructions also omit the most urgent response step: revoking or rotating the compromised credential. Consequently, the secret may remain both recoverable and operational after the user completes every documented remediation step.

Attack Path

  1. A user stages project contents, potentially through the documented git add . workflow.
  2. A password file or another credential-bearing file is committed and pushed to GitHub.
  3. An attacker, collaborator, repository reader, automated crawler, or secret-harvesting service obtains the secret from the exposed commit.
  4. The user follows the documented remediation by adding the file to .gitignore, running git rm --cached, committing the deletion, and pushing it.
  5. The sensit ...[truncated 1054 chars]
Remediation
View remediation

Remediation Suggestions

Replace the documented response procedure with a complete secret-incident workflow:

  1. Revoke or rotate the credential immediately. Assume any secret pushed to a remote repository is compromised. Do not wait for history cleanup before invalidating it.
  2. Remove the secret from repository history. Use a supported history-rewriting tool such as git filter-repo or an equivalent repository-host procedure to purge the file or sensitive value from every affected branch and tag.
  3. Force-push rewritten references carefully. Coordinate with all collaborators before force-pushing branches and tags. Require collaborators to discard or clean affected clones so the removed history is not accidentally restored.
  4. Inspect secondary exposure locations. Review forks, mirrors, pull-request references, releases, artifacts, caches, logs, and archived clones. Contact the hosting provider if additional cleanup is required.
  5. Review credential activity. Inspect authentication and audit logs for unauthorized use from the time of initial exposure until revocation.
  6. Prevent recurrence. Retain an appropriate .gitignore, use narrowly scoped staging instead of indiscriminate staging where practical, and review staged content with git diff --cached before committing.
  7. Add automated controls. Enable repository secret scanning, pre-commit secret detection, push protection, and least-privilege, short-lived credentials.
  8. Clarify limitations in the skill documentation. Explicitly state that git rm --cached removes a file only from the current tracked tree and is insufficient after a secret has entered Git history.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

该技能直接指导用户将本地文件推送到 GitHub,但没有在显著位置明确提醒:推送可能导致源代码、配置、密钥、个人数据或内部文档被上传到第三方平台,甚至因仓库可见性配置不当而公开泄露。虽然文中提到 .gitignore 和“不小心提交了密码文件”的补救措施,但这属于事后处理,不能替代事前风险告知与上传前检查。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

整个技能标题与说明均以中文撰写,未向用户提供语言/locale 选择,也未说明该技能仅面向特定中文使用场景。根据规则,若技能强制特定语言而无用户选择或明确合理的地域限定,属于自然语言层面的政策问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.