Back to skill

Security audit

Git Monitor

Security checks for vulnerabilities and agentic risk

Overview

This Git monitoring skill is mostly aligned with its stated purpose, but it uses unsafe Git command execution, can overwrite local repository changes, and automatically uses messaging credentials for outbound Feishu notifications.

Review before installing. Only use this with trusted repository inputs, avoid monitoring repos with uncommitted local work, and do not enable Feishu notifications for private repositories unless you are comfortable sending commit and file-change metadata to that chat service. The publisher should replace shell-string Git commands, remove reset --hard from normal checks, start from an empty config, and require explicit consent for credential lookup and outbound notifications.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
helper.js:151
Finding

Shell Command Injection Through Repository URL and Branch Parameters

Content
View full analysis
{ try { return execSync(`git ${args.join(' ')}`, { encoding: 'utf8', maxBuffer: 10 * 1024 * 1024, cwd: localPath, stdio: ['ignore', 'pipe', 'pipe'] }); } catch (e) { return e.stdout || e.message; } }; const repoExists = fs.existsSync(path.join(localPath, '.git')); if (!repoExists) { execSync(`git clone "${url}" "${localPath}" --depth=100`, { encoding: 'utf8', maxBuffer: 50 * 1024 * 1024, stdio: ['ignore', 'pipe', 'pipe'] }); const commit = execSync(`git rev-parse HEAD`, { encoding: 'utf8', cwd: localPath }).trim(); return { isInitial: true, repo: repo.name, commit }; } try { execSync(`git fetch origin`, { cwd: localPath, stdio: ['ignore', 'pipe', 'pipe'] }); execSync(`git reset --hard origin/${branch}`, { cwd: localPath, stdio: ['ignore', 'pipe', 'pipe'] }); } catch (e) { try { execSync(`gi ...[truncated 3136 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
helper.js:363
Finding

Destructive Repository Synchronization Silently Discards Local Changes

Content
View full analysis
` rewrites the index and tracked worki ...[truncated 1016 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个较完整、通用的 Git 仓库监控/管理工具,涵盖仓库添加删除、任意平台支持、自动同步、更新通知和持续跟踪等能力。实际代码只是一个一次性执行的仓库检查脚本:若目录不存在则 clone;若已存在则 fetch 指定分支、比较 commit、输出日志和 diff 摘要,然后 fast-forward merge。本质上它确实覆盖了“检查更新”“拉取最新代码”“生成变更摘要”的一部分核心功能,但没有实现仓库注册/删除、持续监控、通知、调度,也没有证明对多个平台的专门支持。因此描述相对代码明显更宽泛,存在能力夸大与主用途范围不一致的情况。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger conditions are extremely broad, including generic terms like GitHub, GitLab, Gitee, 拉取代码, and 代码变化, which can cause the skill to activate during ordinary repository discussion. In context, this is dangerous because the skill can pull code, inspect configured credentials, and send notifications externally, so over-triggering may lead to unintended actions or data exposure.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Using 'git reset --hard origin/${branch}' with a branch value originating from user-controlled input can trigger destructive repository state changes and discard local modifications. Even absent shell injection, the parameter abuse risk is real because the command semantics themselves are dangerous for a monitoring action.

Content

Scanner excerpt · helper.js (reported line 367)May include surrounding context.

js
// fetch + reset --hard origin/branch
    try {
      execSync(`git fetch origin`, { cwd: localPath, stdio: ['ignore', 'pipe', 'pipe'] });
      execSync(`git reset --hard origin/${branch}`, { cwd: localPath, stdio: ['ignore', 'pipe', 'pipe'] });
    } catch (e) {
      // 分支可能不存在,尝试 master
      try {

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The fallback 'git reset --hard origin/master' repeats the same destructive behavior even when the requested branch is unavailable. That means a failed update can still overwrite the checkout to another branch tip, causing confusing state changes and possible data loss.

Content

Scanner excerpt · helper.js (reported line 372)May include surrounding context.

js
// 分支可能不存在,尝试 master
      try {
        execSync(`git fetch origin`, { cwd: localPath, stdio: ['ignore', 'pipe', 'pipe'] });
        execSync(`git reset --hard origin/master`, { cwd: localPath, stdio: ['ignore', 'pipe', 'pipe'] });
      } catch (e2) {
        return { hasUpdates: false, error: `拉取失败: ${e2.message}`, repo: repo.name };
      }

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README instructs users to configure Feishu credentials and states that automatic push notifications are supported, but it does not warn that repository metadata, update summaries, or other potentially sensitive information may be transmitted to a third-party messaging service. In a Git-monitoring skill, automatic outbound notifications create a real data-flow and side-effect risk, especially if users monitor private repositories or assume notifications are local-only.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises capabilities that access environment/config secrets and perform network actions, but it does not declare any tool scope or permission boundaries. That makes the skill harder to audit and can cause users or orchestrators to invoke a repo-monitoring workflow without explicit consent to secret access or outbound communication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description, trigger phrases, and examples are entirely in Chinese and instruct users to invoke the skill with Chinese commands, with no indication that other languages are supported or that Chinese-only behavior is intentional for a region-specific tool. This can violate language/locale policy when the skill implicitly enforces a single language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage guidance emphasizes convenience and automatic behavior but does not clearly warn users that the skill may pull remote code and push summaries to external destinations like Feishu or the current chat. Missing disclosure increases the chance of silent data movement or unexpected synchronization in environments where repo contents or update metadata are sensitive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly states it will cascade through environment variables and host configuration files to obtain Feishu credentials, but it does not present this as sensitive credential access or require user acknowledgement. In a skill context, silent secret discovery from env/config is risky because it expands access beyond the immediate task and can enable unauthorized external messaging.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file description and all user-facing CLI messages are in Chinese, and the code also formats timestamps with the zh-CN locale. This imposes a specific language/locale on users without any documented choice, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill reads Feishu credentials not only from its own local config but also from environment variables and a host-level OpenClaw config in the user's home directory. That expands its access to unrelated secrets and crosses privilege boundaries for a repository-monitoring tool, creating unnecessary secret exposure if the skill is triggered in a broader host context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code implements outbound Feishu messaging, which is an external communication capability beyond simple local Git monitoring. This can leak repository metadata, commit messages, file names, and timing information to a third-party service, especially because notifications are sent automatically when updates are detected.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This request sends Feishu app credentials to Feishu's token endpoint to obtain an access token. Although that is part of normal API use, within this skill it constitutes external transmission of sensitive credentials and enables an undeclared communication path that may expose host-scoped secrets beyond the tool's monitoring purpose.

Content

Scanner excerpt · helper.js (reported line 105)May include surrounding context.

js
try {
    // 获取 tenant_access_token
    const tokenResponse = await fetch('https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal', {
      method: 'POST',
      headers: { 'Content-Type': 'application/json' },
      body: JSON.stringify({ app_id: appId, app_secret: appSecret })

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

This request sends repository update summaries to Feishu, including repository URL, commit messages, author names, timestamps, and changed file paths. In many environments that metadata is sensitive, and automatic outbound transmission to a third-party chat system creates an exfiltration channel not essential to local repository checking.

Content

Scanner excerpt · helper.js (reported line 118)May include surrounding context.

js
}
    
    // 发送消息
    const msgResponse = await fetch('https://open.feishu.cn/open-apis/im/v1/messages', {
      method: 'POST',
      headers: { 
        'Content-Type': 'application/json',

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Repository checks perform 'git reset --hard' against the tracked branch without any confirmation, which will discard uncommitted local changes in the monitored repository checkout. In an agent context, this is dangerous because a seemingly harmless 'check updates' action can become destructive and cause irreversible data loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's user-facing comments and status messages are written in Chinese, including the operational output shown to users. For a general-purpose monitoring script, this imposes a specific language/locale without any opt-in, selection mechanism, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README presents the skill name, usage examples, and invocation phrases entirely in Chinese, implying a fixed language for interaction. There is no indication that users may choose another language or that the Chinese-only scope is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is written only in Chinese ("Git 项目监控工具"), which signals a language-specific presentation without any indication that users can choose their preferred language. Under the policy, language or locale constraints should be optional or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
helper.js:318

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
helper.js:44