Back to skill

Security audit

GitHub Trending Feed

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches public GitHub Trending repository data and outputs JSON, though its advertised language filter appears broken.

Install only if you are comfortable with the skill making outbound requests to GitHub. Expect default GitHub Trending results rather than reliable language-filtered results until the filter implementation is fixed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

整体目的与声明基本一致:代码确实访问 GitHub Trending、提取热门仓库,并输出结构化 JSON。不过存在关键行为偏差:main() 中虽然根据命令行参数构造了一个带参数的 url,但该变量从未传入 fetch_trending_page(),后者始终固定请求 https://github.com/trending,因此所谓“支持可选语言过滤”实际上没有生效。此外,代码把用户提供的语言参数拼到 since 参数上,这与 GitHub Trending 的语言过滤语义不符。也就是说,技能描述中的核心附加能力——按语言过滤——没有被真实实现,属于描述与实际行为不一致。除此之外,代码还会额外调用 GitHub API 获取仓库详情,但这仍属于实现‘返回结构化热门仓库信息’的合理支持行为,不构成额外风险性能力。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs execution of a script that performs outbound network access, but the skill manifest does not declare any tool scope or permissions for that capability. This weakens least-privilege controls and makes it harder for the agent runtime or reviewers to understand and constrain what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language description, headings, usage guidance, and output examples are entirely in Chinese, and the file does not indicate that users may choose another language or locale. Under the policy rule, a skill that effectively mandates a specific language without opt-in is a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code explicitly sets the Accept-Language header to en-US,en;q=0.9, which forces an English locale for fetched content. Elsewhere it emits Chinese fallback strings, showing locale behavior is hard-coded rather than user-selectable, which violates the policy against forcing a language/locale without opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_trending.py (reported line 58)May include surrounding context.

python
def fetch_repo_details(repo_path):
    """Fetch repo details from GitHub API."""
    clean_path = repo_path.lstrip("/")
    api_url = f"https://api.github.com/repos/{clean_path}"
    req = urllib.request.Request(
        api_url,
        headers={

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill supports optional language filtering for GitHub Trending results. In main(), the argument is assigned to lang_filter, but the constructed URL uses '?since={lang_filter}' and is never passed to fetch_trending_page(), which always fetches the unfiltered '/trending' page. This means the advertised filtering behavior does not match actual code behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code names the argument 'lang_filter' and constructs a URL based on it, suggesting the program will fetch filtered trending results. However, the constructed URL variable is unused and fetch_trending_page() always retrieves the default trending page, so the nearby code intent cues contradict actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.