Back to skill

Security audit

Git Workflows

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Git workflow reference skill with some destructive command examples that users should run carefully.

Install only if you want an advanced Git command reference. Before running examples, read each command carefully, make backups or stashes before history-changing operations, double-check rm -rf paths and remotes, and avoid the fixed /tmp script pattern on shared machines.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:136
Finding

Predictable Executable Temporary File Enables Symlink and Replacement Attacks

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 136–142
Vulnerability Type: Predictable and insecure temporary-file handling
Risk Level: Medium

bash
cat > /tmp/test-for-bug.sh << 'EOF'
#!/bin/bash
# Return 0 if bug is NOT present, 1 if it IS
npm test -- --grep "login should redirect" 2>/dev/null
EOF
chmod +x /tmp/test-for-bug.sh
git bisect run /tmp/test-for-bug.sh

Technical Analysis

The documented workflow creates, modifies, and executes a script at the fixed, globally predictable path /tmp/test-for-bug.sh. On a shared Unix-like system, /tmp is normally writable by all local users. Although its sticky bit restricts deletion of other users' files, it does not make predictable file creation safe.

An attacker who can write to /tmp may pre-create the path as a symbolic link before the redirection occurs. If the user has permission to write to the symlink target, cat > /tmp/test-for-bug.sh can truncate and overwrite that target. The subsequent chmod +x may also change the target's executable permissions.

There is also a time-of-check/time-of-use window between script creation and git bisect run. If an attacker can replace or influence the path during that interval, git bisect may execute attacker-controlled commands with the privileges of the user following the instructions.

Attack Path

  1. A local attacker predicts that the workflow will use /tmp/test-for-bug.sh.
  2. Before the victim runs the documented commands, the attacker creates that path as a symbolic link to a file writable by the victim, or prepares to replace the path after creation.
  3. The victim executes the redirection, potentially overwriting the linked target.
  4. The victim runs chmod +x, potentially altering permissions on the unintended target.
  5. Alternatively, the attacker replaces or modifies the script before git bisect run executes it.
  6. The victim executes the attacker-controlled script ...[truncated 539 chars]
Remediation
View remediation

Remediation Suggestions

Create an atomically allocated, user-private temporary directory and place the executable script inside it. Quote all path expansions, restrict script permissions, and register cleanup:

bash
tmpdir="$(mktemp -d)" || exit 1
trap 'rm -rf -- "$tmpdir"' EXIT

script="$tmpdir/test-for-bug.sh"
cat > "$script" <<'EOF'
#!/bin/bash
# Return 0 if bug is NOT present, 1 if it IS
npm test -- --grep "login should redirect" 2>/dev/null
EOF

chmod 700 "$script"
git bisect run "$script"

Additionally:

  • Do not use a fixed filename directly under a shared temporary directory.
  • Ensure mktemp -d succeeds before creating or executing any file.
  • Keep the temporary directory accessible only to its owner.
  • Remove temporary artifacts through a quoted trap, including on interruption or failure.
  • Where practical, keep the test script in the trusted repository instead of generating executable content in /tmp.
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 217)May include surrounding context.

md
# Undo a bad rebase (find the commit before rebase in reflog)
git reflog
# Find: "ghi789 HEAD@{5}: checkout: moving from feature to main" (pre-rebase)
git reset --hard ghi789

# Recover a deleted branch
git reflog

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

md
# Undo a bad rebase (find the commit before rebase in reflog)
git reflog
# Find: "ghi789 HEAD@{5}: checkout: moving from feature to main" (pre-rebase)
git reset --hard ghi789

# Recover a deleted branch
git reflog

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 306)May include surrounding context.

git submodule update --remote

Remove a submodule

git rm lib/shared rm -rf .git/modules/lib/shared

Remove entry from .gitmodules if it persists

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 307)May include surrounding context.

Remove a submodule

git rm lib/shared rm -rf .git/modules/lib/shared

Remove entry from .gitmodules if it persists

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown includes git reset --hard recovery examples, which can permanently discard uncommitted changes, but the surrounding text does not warn users about that risk. Under the markdown-specific warning rule, destructive operations that can affect user data should include an explicit caution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The submodule removal example includes rm -rf .git/modules/lib/shared, a destructive filesystem operation, but the documentation does not explicitly warn that it permanently deletes repository metadata. Markdown guidance that instructs file deletion should disclose the risk to user data or repository integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document includes git stash clear, which irreversibly removes all stashed work, but provides no warning about the data-loss implications. This omission can lead users to execute a destructive command without realizing recovery may be difficult or impossible.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.