T09 · Insecure Skill Coding Practices
- Location
SKILL.md:97- Finding
Overbroad Automatic Staging Can Commit and Transmit Sensitive Files
- Content
View full analysis
` when the user requests a push. Consequently, an accidentally staged sensitive file can be committed and transmitted to the configured Git remote. The network operation itself is consistent with the declared functionality, but combining broad staging with a later push creates a sensitive-information disclosure path. No direct privilege escalation is performed, and pushing remains conditional on explicit user intent. The issue is that the contents selected for that push can exceed the intended scope. ### Attack Path 1. A repository contains an untracked or modified sensitive file that does not match one of the examples listed in the warning. 2. The user asks the agent to commit changes, without intending to include that file. 3. The Skill runs or recommends `git add -A`, staging the sensitive file alongside the intended changes. 4. The generated commit ...[truncated 849 chars]- Remediation
View remediation
