T09 · Insecure Skill Coding Practices
- Location
auto_fix.js:37- Finding
Repository-Controlled Code Executes with GitHub Credentials in the Environment
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This GitHub triage skill has a coherent goal, but it uses a GitHub token to make remote changes and run repository code with insufficient scoping and safeguards.
Install only with a narrowly scoped, short-lived GitHub token and only for repositories you fully trust. Avoid enabling the auto-fix workflow until it runs repository code in a credential-free sandbox, removes token-bearing clone metadata, cleans up temporary workspaces, validates command inputs, and offers dry-run or explicit approval controls.
auto_fix.js:37Repository-Controlled Code Executes with GitHub Credentials in the Environment
auto_fix.js:25Shell Command Injection Through Unsanitized Repository, Branch, and Identity Values
auto_fix.js:25GitHub Token Exposed in Process Arguments and Retained Git Metadata
auto_fix.js:52Unpinned Runtime Package Retrieval Through npx
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
console.error('autoFix failed', err.message);
return { changed: false, error: err.message };
} finally {
// cleanup: leave for inspection, or uncomment to remove
// fs.rmSync(workdir, { recursive: true, force: true });
}
}
The implementation does not just inspect repository issues; it actively changes repository state by adding labels and assignees. With no manifest available, these write capabilities are unjustified by any documented purpose and therefore represent context-inappropriate capability.
The script runs npx prettier --write . inside an untrusted cloned repository when no format script exists. npx may resolve and execute a package version that is not pinned, and because this occurs in a hostile repo context after dependency installation, it can execute attacker-controlled code or an unexpected package version with full access to the environment, including GitHub credentials.
This finding refers to the same dangerous behavior: fallback execution of npx prettier --write . against untrusted repository contents. In this skill, that is especially risky because the workflow clones arbitrary repos, installs dependencies, runs repo-defined scripts, and has GH_TOKEN in memory, so any package execution can lead to credential theft or arbitrary code execution.
No manifest is available, so there is no stated skill purpose that would justify accessing environment-provided credentials. The code explicitly reads GH_TOKEN and uses it to authenticate API calls, which is a sensitive capability beyond what can be validated from the available intent context.
This code performs write operations against GitHub by adding labels and assignees to issues, which changes repository state. Aside from a generic runtime log at schedule start, there is no user-facing disclosure, confirmation, or inline warning near the modifying actions to make the behavior explicit.
The dependency uses a caret version range, which allows newer minor and patch releases to be installed over time. This increases supply-chain risk because a compromised upstream release or breaking behavior change could be pulled in without explicit review, which is relevant for a GitHub triage tool that likely handles repository access tokens and automation privileges.
"author": "openclaw",
"license": "MIT",
"dependencies": {
"@octokit/rest": "^21.0.0",
"node-cron": "^3.0.0",
"dotenv": "^16.0.0"
}
The node-cron dependency is specified with a caret range, so future installs may resolve to different versions than originally tested. For an automated scheduled agent, this can introduce supply-chain exposure or unexpected runtime behavior if an upstream release becomes malicious or insecure.
"license": "MIT",
"dependencies": {
"@octokit/rest": "^21.0.0",
"node-cron": "^3.0.0",
"dotenv": "^16.0.0"
}
}
The dotenv dependency is not fully pinned, allowing automatic adoption of later patch/minor versions. While common in development, this still creates a measurable supply-chain risk because changed or compromised upstream packages could affect environments that load secrets or tokens.
"dependencies": {
"@octokit/rest": "^21.0.0",
"node-cron": "^3.0.0",
"dotenv": "^16.0.0"
}
}
Detected: suspicious.dangerous_exec