Back to skill

Security audit

GH Triage

Security checks for vulnerabilities and agentic risk

Overview

This GitHub triage skill has a coherent goal, but it uses a GitHub token to make remote changes and run repository code with insufficient scoping and safeguards.

Install only with a narrowly scoped, short-lived GitHub token and only for repositories you fully trust. Avoid enabling the auto-fix workflow until it runs repository code in a credential-free sandbox, removes token-bearing clone metadata, cleans up temporary workspaces, validates command inputs, and offers dry-run or explicit approval controls.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
auto_fix.js:37
Finding

Repository-Controlled Code Executes with GitHub Credentials in the Environment

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
auto_fix.js:25
Finding

Shell Command Injection Through Unsanitized Repository, Branch, and Identity Values

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
auto_fix.js:25
Finding

GitHub Token Exposed in Process Arguments and Retained Git Metadata

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
auto_fix.js:52
Finding

Unpinned Runtime Package Retrieval Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · auto_fix.js (reported line 101)May include surrounding context.

js
console.error('autoFix failed', err.message);
    return { changed: false, error: err.message };
  } finally {
    // cleanup: leave for inspection, or uncomment to remove
    // fs.rmSync(workdir, { recursive: true, force: true });
  }
}

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The implementation does not just inspect repository issues; it actively changes repository state by adding labels and assignees. With no manifest available, these write capabilities are unjustified by any documented purpose and therefore represent context-inappropriate capability.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The script runs npx prettier --write . inside an untrusted cloned repository when no format script exists. npx may resolve and execute a package version that is not pinned, and because this occurs in a hostile repo context after dependency installation, it can execute attacker-controlled code or an unexpected package version with full access to the environment, including GitHub credentials.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This finding refers to the same dangerous behavior: fallback execution of npx prettier --write . against untrusted repository contents. In this skill, that is especially risky because the workflow clones arbitrary repos, installs dependencies, runs repo-defined scripts, and has GH_TOKEN in memory, so any package execution can lead to credential theft or arbitrary code execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

No manifest is available, so there is no stated skill purpose that would justify accessing environment-provided credentials. The code explicitly reads GH_TOKEN and uses it to authenticate API calls, which is a sensitive capability beyond what can be validated from the available intent context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code performs write operations against GitHub by adding labels and assignees to issues, which changes repository state. Aside from a generic runtime log at schedule start, there is no user-facing disclosure, confirmation, or inline warning near the modifying actions to make the behavior explicit.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The dependency uses a caret version range, which allows newer minor and patch releases to be installed over time. This increases supply-chain risk because a compromised upstream release or breaking behavior change could be pulled in without explicit review, which is relevant for a GitHub triage tool that likely handles repository access tokens and automation privileges.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
"author": "openclaw",
  "license": "MIT",
  "dependencies": {
    "@octokit/rest": "^21.0.0",
    "node-cron": "^3.0.0",
    "dotenv": "^16.0.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The node-cron dependency is specified with a caret range, so future installs may resolve to different versions than originally tested. For an automated scheduled agent, this can introduce supply-chain exposure or unexpected runtime behavior if an upstream release becomes malicious or insecure.

Content

Scanner excerpt · package.json (reported line 14)May include surrounding context.

json
"license": "MIT",
  "dependencies": {
    "@octokit/rest": "^21.0.0",
    "node-cron": "^3.0.0",
    "dotenv": "^16.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
87% confidence
Finding

The dotenv dependency is not fully pinned, allowing automatic adoption of later patch/minor versions. While common in development, this still creates a measurable supply-chain risk because changed or compromised upstream packages could affect environments that load secrets or tokens.

Content

Scanner excerpt · package.json (reported line 15)May include surrounding context.

json
"dependencies": {
    "@octokit/rest": "^21.0.0",
    "node-cron": "^3.0.0",
    "dotenv": "^16.0.0"
  }
}

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
auto_fix.js:31