Back to skill

Security audit

Sui Coverage

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Sui Move coverage helper, but it tells agents to always stage and commit repository changes without an explicit user approval step.

Review this skill before installing. Its coverage and reporting tools appear purpose-aligned, but do not let an agent follow the `Always commit test improvements` instruction automatically; require a diff review, stage only intended files, and commit only after explicit approval.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:276
Finding

Unconditional Git Staging and Commit May Capture Unrelated Repository Changes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 276–279
Vulnerability Type: Unauthorized repository modification and excessive staging scope
Risk Level: Medium

Vulnerable Code

markdown
Always commit test improvements:
```bash
git add sources/ tests/
git commit -m "Improve test coverage for <module>"
text

### Technical Analysis

The skill instructs the agent to always stage and commit changes after improving test coverage. This behavior is unnecessary for coverage analysis and violates least-privilege principles because it changes repository state and Git history without requiring explicit user authorization.

The staging command operates on the complete `sources/` and `tests/` directory trees rather than on files modified specifically by the current task. Consequently, pre-existing changes—including unrelated, incomplete, sensitive, or unreviewed work—may be incorporated into the generated commit.

Although the instructions do not grant operating-system privileges or execute remote code, they authorize repository modifications beyond the minimum scope needed to perform coverage analysis.

### Attack Path

1. A user has pre-existing uncommitted changes under `sources/` or `tests/`.
2. The user asks an agent using this skill to analyze or improve test coverage.
3. The agent follows the mandatory instruction to run `git add sources/ tests/`.
4. Git stages both the agent's intended test changes and the user's unrelated modifications.
5. The agent runs the prescribed `git commit` without obtaining explicit approval.
6. The resulting commit records all staged content, potentially exposing or preserving unrelated sensitive work in local or subsequently pushed history.

This path requires the agent to follow the documented workflow and requires unrelated modifications to exist within one of the broadly staged directories.

### Impact Assessment

The behavior can modify the active repository's index and local commit history. Its scope 
...[truncated 636 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the unconditional requirement to commit changes.
  2. Treat repository commits as an optional action requiring explicit user approval.
  3. Before requesting approval, display the relevant diff and clearly list the files that would be staged.
  4. Stage only files created or modified by the current task, using explicit paths rather than entire directories.
  5. Recheck the staged diff with git diff --cached before committing.
  6. Preserve unrelated working-tree and index changes.
  7. Replace the current instructions with a guarded workflow such as:
markdown
After making test improvements:

1. Show the user the files changed and the relevant diff.
2. Do not stage or commit changes unless the user explicitly requests it.
3. If approved, stage only the files modified for this task:
   `git add -- <explicit-file-paths>`
4. Review `git diff --cached` before creating the commit.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code does match part of the description: it analyzes Sui Move coverage output and generates reports. However, the actual code chunk only parses colored source coverage text and summarizes uncovered lines. It does not write or generate tests, modify files, perform any security-audit logic, or carry out broader auditing behavior. Therefore the declared description overstates the implemented capabilities in this chunk, making it a description-behavior mismatch.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · analyze_source.py (reported line 41)May include surrounding context.

python
os.dup2(slave, 2)
        os.close(slave)
        os.chdir(package_path)
        os.execvp('sui', ['sui', 'move', 'coverage', 'source', '--module', module_name])
    else:
        # Parent process
        os.close(slave)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documentation clearly directs an agent to read files, write files, and execute shell commands, but it does not declare any explicit tool scope or permission boundaries. This is dangerous because an agent or platform may grant broader capabilities than users expect, increasing the chance of unintended file modification or command execution during routine use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to run git add and git commit as a normal part of the workflow, even though committing changes is not necessary for coverage analysis itself. This is dangerous because it can permanently record unintended or unreviewed modifications, including sensitive data, flawed tests, or broad workspace changes, especially in automated environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation tells the user or agent to commit changes automatically without any warning, confirmation, or review requirement. In an agent setting, this can turn routine testing into an unauthorized source-control action, making it easier to persist incorrect, malicious, or sensitive changes and reducing human oversight over repository history.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.