Back to skill

Security audit

lazyGithub Bootstrap

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to publish GitHub repositories, but its wrapper script and instructions can make public remote changes without strong confirmation or path-safety controls.

Review carefully before installing. Use only when you explicitly want an agent to publish or modify a GitHub repository. Confirm the owner, repo name, visibility, source directory, files to be pushed, and absence of secrets before any gh command runs; avoid the wrapper script unless it is updated to reject paths and require explicit public/private choice.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lazygithub.sh:78
Finding

Unvalidated Repository Name Can Publicly Push an Existing Local Git Repository

Content
View full analysis

Vulnerability Details

File Location: scripts/lazygithub.sh, lines 7 and 78-106
Vulnerability Type: Unsafe local repository reuse and unintended public data exposure
Risk Level: High

bash
VISIBILITY="public"

if [[ "$ADD_LOCAL_README" == "true" ]]; then
  mkdir -p "$NAME"
  if [[ ! -f "$NAME/README.md" ]]; then
    cat > "$NAME/README.md" <<EOF
# $NAME

$DESCRIPTION
EOF
  fi

  if [[ ! -d "$NAME/.git" ]]; then
    git -C "$NAME" init
    git -C "$NAME" add README.md
    git -C "$NAME" commit -m "chore: initial commit"
  fi
fi

CREATE_ARGS=(repo create "$NAME" "--$VISIBILITY" --description "$DESCRIPTION")

if [[ -n "$HOMEPAGE" ]]; then
  CREATE_ARGS+=(--homepage "$HOMEPAGE")
fi

if [[ "$ADD_LOCAL_README" == "true" ]]; then
  CREATE_ARGS+=(--source "$NAME" --remote origin --push)
fi

gh "${CREATE_ARGS[@]}"

Technical Analysis

The user-controlled --name value serves two distinct purposes: the GitHub repository name and the local source-directory path. The script does not verify that this value is a simple repository name, does not reject path separators, and does not establish that the local directory was created by the current invocation.

mkdir -p "$NAME" succeeds when the directory already exists. If that directory contains .git, the initialization branch is skipped, after which the existing repository is passed to gh repo create through --source "$NAME". The --push option can then upload the repository's tracked files and Git history.

This behavior is especially dangerous because repository visibility defaults to public. Shell command injection is mitigated by array-based argument construction and quoting, but these measures do not prevent semantic path injection or unsafe reuse of an existing repository.

Attack Path

  1. An attacker, untrusted instruction, or mistaken caller supplies --name with a value resolving to an existing local Git reposi ...[truncated 1210 chars]
Remediation
View remediation

Remediation Suggestions

  1. Separate the remote repository name from the local source path. Introduce an explicit --source argument rather than interpreting --name as both values.
  2. Validate repository names against a strict allowlist and reject path separators, . or .. components, absolute paths, control characters, and option-like values.
  3. Refuse to reuse any existing local directory by default. Require an explicit option such as --allow-existing-source before operating on an existing Git repository.
  4. Resolve an explicitly supplied source with a canonical-path operation and verify that it is within an expected workspace or another user-approved location.
  5. Before pushing an existing repository, display or inspect the remote, tracked files, commit history, and current branch, then require explicit confirmation.
  6. Do not default potentially reused repositories to public visibility. Require the caller to explicitly choose --public or --private, with an additional confirmation before public publication.
  7. Check whether an origin remote already exists and refuse to replace or conflict with it without explicit authorization.
  8. Consider creating new repositories in a securely generated empty working directory so pre-existing content cannot be selected accidentally.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The declared purpose emphasizes publishing, bootstrapping, or tidying repositories so README and About metadata stay in sync, including handling existing local projects and fixing existing repo presentation. The code is narrower: it is primarily a repo-creation/bootstrap script. It creates a new repo, optionally creates a README from the provided description, initializes git, commits, pushes, and adds topics. It does not read an existing README, compare README against repository metadata, reconcile differences, or update an existing repository's About section to match local content. So while part of the declared purpose (bootstrapping/publishing a new repo with metadata) is accurate, the broader synchronization/tidying claims are not supported by the code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill is framed with very broad invocation language around creating, publishing, and tidying repositories, which can cause an agent to select it for loosely related requests and perform unintended remote actions. In the context of GitHub operations, overbroad scope increases the chance of accidental repository creation, metadata modification, or publication without sufficiently specific user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow directs the agent to create and edit remote GitHub repositories, including setting visibility and generating missing README content, without an explicit safety gate requiring user confirmation before remote-state changes. This is dangerous because a mistaken invocation or incorrect inference could publish code publicly, alter an existing repository's presentation, or create persistent external artifacts using the user's authenticated GitHub context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This prompt template explicitly instructs an agent to create or publish a project to GitHub and to update repository metadata, but it contains no guardrails about repository visibility, accidental publication of private code, or confirmation before pushing to an external service. In an agent skill, that omission is risky because it normalizes remote side effects and possible data disclosure without requiring a user acknowledgment of privacy and publication consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This template directs the agent to inspect a project, create or update a GitHub repository with gh, and continue until metadata changes succeed, but it does not warn about the implications of remote changes or external disclosure. Because it encourages persistence in making remote modifications, it increases the chance an agent will publish or alter a repository state the user did not fully intend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Claude-flavored prompt tells an agent to publish a project to GitHub and modify README/About presentation while omitting any warning that this may expose local project contents or make externally visible changes. In the context of a repo-bootstrap skill whose purpose is publication, that omission is especially important because the action is inherently outward-facing and can disclose sensitive or unfinished material.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.