Back to skill

Security audit

panda-git-commit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Git commit helper, but it asks the agent to run repository-changing Git commands using unsafe command examples and can auto-download an unpinned runtime.

Review before installing. Prefer using a locally installed trusted Bun binary, avoid the npx fallback, run in dry-run mode first, and manually review any generated commit message and file list before allowing the agent to run git add or git commit. Be especially cautious on repositories containing untrusted diffs or unusual filenames.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
prompts/commit-message.md:41
Finding

Untrusted Git Diff Content Is Inserted Into the Agent Prompt Without Injection Defenses

Content
View full analysis
{ const stageFlag = staged ? ["--staged"] : []; const [numstatResult, nameStatusResult, rawDiffResult] = await Promise.all([ exec("git", ["diff", ...stageFlag, "--numstat"]).catch(() => ({ stdout: "" })), exec("git", ["diff", ...stageFlag, "--name-status"]).catch(() => ({ stdout: "" })), exec("git", ["diff", ...stageFlag]).catch(() => ({ stdout: "" })), ]); ``` The split-commit prompt similarly includes the complete diff: ```text Complete Diff: {raw_diff} ``` Commit subjects collected from repository history are also retained as examples: ```ts for (const line of lines) { if (CC_BREAKING_RE.test(line)) { counts.cc++; hasBreaking = true; const m = line.match(CC_BREAKING_RE); if (m) detectedTypes.add(m[1]); if (examples.cc.length < 3) examples.cc.push(line); } else if (CC_RE.test(line)) { counts.cc++; const m = line.match(CC_RE); if (m) detectedTypes.add(m[1]); if (examples.cc.length < 3) examples.cc.push(line); } else if (JIRA_RE.test(line)) { counts.jira++; if (examples.jira.length < 3) examples.jira.push(line); } else if (EMOJI_PREFIX_RE.test(line)) { counts.emoji++; if (examples.emoji.length < 3) examples.emoji.push(line); } else { counts.free++; if (examples.free.length < 3) examples.free.push(line); } } ``` ### Technical Anal ...[truncated 2113 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Unpinned Bun Runtime Can Be Downloaded and Executed Automatically Through npx

Content
View full analysis
.ts` 3. Resolve the `${BUN_X}` runtime: if `bun` is installed → `bun`; if `npx` is available → `npx -y bun`; otherwise prompt the user to install bun 4. Replace all `{baseDir}` and `${BUN_X}` references in this document with actual values ``` ### Technical Analysis The fallback command `npx -y bun` does not pin an exact audited package version or verify package integrity. If Bun is not installed locally, `npx` may resolve and download package content from the configured npm registry and immediately execute it. The `-y` option suppresses the normal confirmation step. Consequently, the effective runtime may differ from the runtime that was present when the Skill was reviewed. A compromised registry account, dependency-resolution manipulation, malicious registry configuration, or a compromised future release could introduce arbitrary code into the execution path. No evidence was found that the current project intentionally retrieves a malicious payload. The risk arises from unsafe supply-chain resolution and automatic execution. ### Attack Path 1. Bun is not installed on the user's system, but `npx` is available. 2. The Agent follows the documented fallback and executes `npx -y bun`. 3. `npx` resolves the package from the user's configured package registry. 4. A compromised or substituted package version is downloaded. 5. Package installation or runtime code executes with the permissions of the current user. 6. Malicious package code can access files and processes available to that user. ### Impact Assessment A compromised package can execute arbitrary code with the current user's privileges. Depending on the environment, this may ...[truncated 393 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:277
Finding

Documented Commit Workflow Interpolates Generated Messages and Repository Filenames Into Shell Commands

Content
View full analysis
"` - Split commits: execute `git add && git commit -m ""` sequentially - `--dry-run` mode: only output the message and do not execute Git commands ``` ### Technical Analysis The Skill instructs the Agent to place generated commit messages and repository-derived filenames into shell command templates. It does not require argument-array execution, escaping, or the `--` end-of-options separator. Both data sources may be attacker influenced: - Filenames are controlled by repository contents. - Commit messages are generated from untrusted diff content and may be affected by prompt injection. If an implementation constructs a shell command by replacing `` or `` with raw values, shell metacharacters, quotes, substitutions, or option-like filenames may change command interpretation. For example, a filename beginning with `-` can be treated as a Git option unless it appears after `--`. Quotes or shell operators in a generated message can break out of the intended argument if inserted without safe escaping. The TypeScript scripts reviewed use `execFile` with argument arrays for their existing read-only Git commands, which is safer. The vulnerability is specifically in the documented Agent execution workflow, where no equivalent safety requirement is imposed. ### Attack Path 1. An attacker introduces a crafted filename into the repository or places prompt-injection text in a staged diff. 2. The split workflow returns the repository-controlled filename, or the model produces an attacker-influenced message. 3. The Agent substitutes the value into `git add && git commit -m ""`. 4. The Agent executes the assembled text through a shell. 5. ...[truncated 807 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The declared description promises a commit-message generation tool with Conventional Commits formatting, monorepo scope detection, and commit splitting support. The supplied code instead serves as a git diff/history analyzer: it runs git log and git diff commands, parses changed files and stats, detects a likely language from recent commit subjects, and heuristically infers a commit type. While these behaviors could support a commit-message generator, the code shown does not actually compose or output a Conventional Commit message, determine package/module scope in a monorepo, or split changes into separate commits. Therefore the implemented behavior is only a partial supporting subsystem and does not accurately match the declared end-user capability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

这段代码的核心功能是“检测/推断提交规范”,而不是“生成提交信息”。它会读取仓库中的 commitlint、commitizen、git hooks 和 package.json 配置,并调用 git log 分析最近 50 条提交标题,以判断项目采用的提交格式(如 conventional commits、emoji、JIRA 前缀等)及相关规则,再给出最佳实践建议。声明中强调的主要能力——生成 commit message、自动检测 monorepo scope、拆分变更为多个 commit——在此代码中都没有体现。因此描述与实际行为存在实质性不符。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code is broadly related to the declared domain: it inspects git changes, infers commit type, detects monorepo scope, and supports split-commit suggestions. However, the declared description emphasizes intelligent generation of Conventional Commits-style Git commit messages. In this chunk, the primary observable behavior is producing JSON analysis/suggestion output for single or split modes, plus project configuration initialization/refresh through EXTEND.md. Those config file write capabilities are undeclared. Also, the code does not clearly generate a finalized commit message subject/body; it mainly emits type/scope/group information and split suggestions. Therefore the description is only partially accurate and omits a material extra capability.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
| `scripts/analyzer.ts` | Git diff 分析、语言检测 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| `scripts/analyzer.ts` | Git diff 分析、语言检测 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
| `scripts/scope-detector.ts` | Monorepo 结构检测、scope 推导 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
| `scripts/convention-detector.ts` | 项目 commit 规范检测(commitlint / commitizen / git history) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
| `scripts/splitter.ts` | 按功能维度拆分变更 |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/conventional-commits.md (reported line 64)May include surrounding context.

text
feat(auth): add JWT refresh token support

Implement automatic token refresh when the access token expires.
The refresh token is stored in httpOnly cookie for security.

Closes #142

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/conventional-commits.md (reported line 75)May include surrounding context.

text
feat(auth): add JWT refresh token support

Implement automatic token refresh when the access token expires.
The refresh token is stored in httpOnly cookie for security.

Closes #142

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/convention-detector.ts (reported line 37)May include surrounding context.

ts
function extractCommitlintRules(config: Record<string, unknown>): ConventionRule {
  const rules: ConventionRule = {};
  const r = config.rules as Record<string, unknown[]> | undefined;
  if (!r) return rules;

  if (r["type-enum"]) {
    const [, , types] = r["type-enum"] as [number, string, string[]];

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/convention-detector.ts (reported line 70)May include surrounding context.

ts
function extractCommitlintRules(config: Record<string, unknown>): ConventionRule {
  const rules: ConventionRule = {};
  const r = config.rules as Record<string, unknown[]> | undefined;
  if (!r) return rules;

  if (r["type-enum"]) {
    const [, , types] = r["type-enum"] as [number, string, string[]];

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/convention-detector.ts (reported line 116)May include surrounding context.

ts
function extractCommitlintRules(config: Record<string, unknown>): ConventionRule {
  const rules: ConventionRule = {};
  const r = config.rules as Record<string, unknown[]> | undefined;
  if (!r) return rules;

  if (r["type-enum"]) {
    const [, , types] = r["type-enum"] as [number, string, string[]];

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill instructs the agent to inspect environment-dependent paths and variables such as ${XDG_CONFIG_HOME} and $HOME, but it declares no explicit tool scope or permissions boundary. In practice this weakens reviewability and can cause the agent to access local environment context and user-level configuration without clear user awareness, which is risky for a skill that also reads and writes repository-adjacent files.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include broad generic terms like commit, 提交, and git commit, which can cause accidental invocation in unrelated conversations or contexts. Because this skill can inspect git diff/history and may proceed toward writing commits or config files, unintended activation increases the risk of unnecessary repository access and unintended state changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The runtime fallback npx -y bun fetches and executes a package/toolchain without pinning a specific version, which creates a supply-chain risk and undermines reproducibility. If the resolved package version is malicious, compromised, or simply changed incompatibly, the agent may execute untrusted code on the user's machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents that --init and --refresh will generate or overwrite .panda-skills/panda-git-commit/EXTEND.md, but it does not present a strong explicit warning about filesystem modification or user confirmation requirements. In a repository tool, silent or poorly signposted writes can alter project state, create unexpected tracked files, and overwrite configuration-derived content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states that language may be auto-detected or explicitly set only to zh, en, ja, or ko. This is a natural-language policy concern because it imposes a locale/language restriction in the skill description without presenting it as an optional user choice beyond that limited set or documenting a region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire document is written in Chinese and provides no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file defines a restricted language set (zh, en, ja, ko) and automatically selects one based on recent git commit messages, defaulting to English on no data or errors. This is a natural-language policy concern because it imposes a language/locale decision without exposing any user choice, opt-in, or justification for the restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code emits multiple user-facing best-practice strings only in Chinese, with no language selection or opt-in mechanism. That creates a natural-language policy issue because the skill enforces a locale/language choice rather than offering one to the user.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code always emits a language field into the generated EXTEND.md content, which can impose a specific language/locale behavior downstream. The file contains no visible opt-in, alternative choice, or justification for enforcing that language, matching the policy's language/locale violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing status messages are hardcoded in Chinese, and additional user-facing messages elsewhere in the file are also emitted only in Chinese. This creates a language policy issue because the skill does not offer a language choice or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Several user-visible hint, error, and warning messages are hardcoded in Chinese, including guidance for initialization and git staging. Because the file provides no opt-in or locale selection for these messages, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code always calls formatSplitSuggestion with "zh", which forces Chinese output whenever a split suggestion is generated. That is a natural-language locale policy issue because the user is not offered a language choice and the constraint is not justified in this file.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/analyzer.ts:29

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/convention-detector.ts:193

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/utils.ts:34