Back to skill

Security audit

Commit code safe and nice

Security checks for vulnerabilities and agentic risk

Overview

This Git commit helper is purpose-aligned overall, but it can automatically rebase, broadly stage files, and record agent/model metadata in commits, so it deserves review before installation.

Install only if you are comfortable with the agent changing Git state automatically. Review the staged file list and diff before commits, avoid using it in repositories with untracked secrets, and consider requiring explicit approval for rebase, `git add -A`, amend, and any push.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:97
Finding

Overbroad Automatic Staging Can Commit and Transmit Sensitive Files

Content
View full analysis
` when the user requests a push. Consequently, an accidentally staged sensitive file can be committed and transmitted to the configured Git remote. The network operation itself is consistent with the declared functionality, but combining broad staging with a later push creates a sensitive-information disclosure path. No direct privilege escalation is performed, and pushing remains conditional on explicit user intent. The issue is that the contents selected for that push can exceed the intended scope. ### Attack Path 1. A repository contains an untracked or modified sensitive file that does not match one of the examples listed in the warning. 2. The user asks the agent to commit changes, without intending to include that file. 3. The Skill runs or recommends `git add -A`, staging the sensitive file alongside the intended changes. 4. The generated commit ...[truncated 849 chars]
Remediation
View remediation

other

Note
Location
SKILL.md:167
Finding

Mandatory Agent and Model Metadata Disclosure in Commit History

Content
View full analysis
AI-model: claude-sonnet-4-6 ``` If the exact model ID is available (from the system context), use it. Otherwise use the family name. ``` ### Technical Analysis The Skill requires the agent to obtain its model identity from available environment or system context and permanently include it in every generated commit. This information is not necessary to stage, commit, synchronize, or push repository changes. When such a commit is pushed, the model identifier and provider attribution become visible to the Git hosting provider and repository readers. Git history is durable and widely replicated, so removing the metadata later may require rewriting published history. The instruction does not expose arbitrary system prompts or secrets by itself. The confirmed disclosure is limited to the agent/provider attribution and exact or family-level model identifier. Nevertheless, requiring system-context-derived metadata exceeds the minimum information required for the Skill's declared Git functionality. ### Attack Path 1. The user asks the Skill to create a commit. 2. The Skill reads the exact model identifier from the system context when available. 3. It inserts the model identifier and provider attribution into the commit footer. 4. The commit permanently records this runtime identity information in local Git history. 5. If the user requests a push, the metadata is transmitted to the configured remote. 6. Repository readers can use the metadata to fingerprint the automation provider and model used to create the commit. ### Impact Assessment The issue discloses agent provenance and model-version ...[truncated 488 chars]
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger text is excessively broad, including everyday phrases like 'save my changes' and 'commit this', which can cause the skill to activate in ambiguous contexts and perform repository-affecting actions the user did not clearly authorize. Because this skill can stage files, rewrite local history via amend, rebase onto remote changes, and optionally push, over-triggering materially increases the chance of unintended code or secret commits.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 239)May include surrounding context.

md
- Never commit secrets: `.env`, `*.pem`, `credentials.*`, `*.key`
- Never skip hooks with `--no-verify` unless the user explicitly asks
- Never use `git reset --hard` or other destructive commands without explicit user request
- If a pre-commit hook fails: fix the issue, re-stage, create a **new** commit (never `--amend` after hook failure)
- If the rebase produces conflicts: `git rebase --abort` and stop — do not proceed

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises automatic fetch and rebase-based synchronization before committing, but the description does not clearly warn that invoking the skill may modify repository state before the user reviews or approves that behavior. Automatic rebases can rewrite local commit history and change the working tree, which is risky in an agent context where invocation may already be too permissive.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.