Back to skill

Security audit

Grokified code review

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed code-review helper that sends selected git diffs to Grokified, so users should avoid using it on sensitive code or secrets.

Install only if you are comfortable sending reviewed git diffs to Grokified. Do not use it on changes containing secrets, customer data, private keys, or proprietary code that your organization does not allow to be sent to third-party model APIs; the built-in filtering is filename-based and will not catch secrets embedded in ordinary source files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill explicitly transmits git diffs, including uncommitted or branch changes, to a third-party API. Even though the README warns about common secret files and says nothing is stored, ordinary source files can still contain credentials, proprietary code, or sensitive business logic, so this creates a real data exfiltration risk.

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

md
1. Takes the diff for the range you ask for: your uncommitted changes, `main...HEAD`, the last commit, or any other git revision range.
2. Leaves out files that usually hold secrets (`.env*`, `*.pem`, `*.key`, `*.p12`, `id_rsa*`, `id_ed25519*`).
3. Stops if the diff is larger than 80,000 bytes, so a request stays under the 32,000 input-token cap per request that free accounts have.
4. Sends the diff to `https://api.grokified.com/v1/chat/completions` with the `grok-build-0.1` model and a short reviewer prompt.
5. Prints the review, and the token counts on stderr.

Nothing is stored by the script. The diff goes to the Grokified API and nowhere else. A secret written directly into ordinary source code is not detected, so do not review a diff that contains one.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes shell scripts and external binaries (bash, git, curl, jq) but does not declare any tool scope such as permissions or allowed-tools. That creates an authorization gap where the runtime or reviewer cannot easily constrain what the skill is allowed to execute, increasing the chance of overbroad command execution if the skill is installed or adapted in a permissive environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This skill transmits local git diffs to an external service (api.grokified.com), which can expose proprietary code, secrets accidentally committed into source, or sensitive implementation details. Although the skill includes a warning and some filename-based exclusions, those controls are incomplete because secrets in ordinary source files are not reliably detected before transmission.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
# Grokified code review

Sends a git diff to a Grok model through the Grokified API (`https://api.grokified.com/v1`, OpenAI-compatible) and returns a review of real problems: bugs, security issues, data loss, race conditions, missing error handling and missing tests.

## When to use

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
## Before the first run

1. Check that `GROKIFIED_API_KEY` is set in the environment. If it is not, tell the user to create a key at https://grokified.com/login and export it. Never ask the user to paste the key into the chat, and never print it.
2. Tell the user, once per session, that the diff leaves the machine and goes to `api.grokified.com`. Files named like `.env*`, `*.pem`, `*.key`, `*.p12`, `id_rsa*` and `id_ed25519*` are left out automatically, but a secret written into ordinary source code is not detected. If the diff may contain one, ask before sending.

## Run it

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/review.sh (reported line 11)May include surrounding context.

sh
#           GROKIFIED_REVIEW_MAX_BYTES (default 80000).
set -euo pipefail

BASE_URL="https://api.grokified.com/v1"
MODEL="${GROKIFIED_MODEL:-grok-build-0.1}"
MAX_BYTES="${GROKIFIED_REVIEW_MAX_BYTES:-80000}"
RANGE="${1:-}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This POST request transmits repository diff contents to an external service, which is a real data exfiltration boundary even if it is the intended feature of the skill. The danger is contextual: code review tools often process sensitive code, and the current exclusions only cover a narrow set of secret filenames, not secrets present in tracked application files or diffs.

Content

Scanner excerpt · scripts/review.sh (reported line 68)May include surrounding context.

sh
http_code="$(
  jq -n --arg model "$MODEL" --arg system "$SYSTEM" --rawfile diff "$diff_file" \
    '{model: $model, messages: [{role: "system", content: $system}, {role: "user", content: ("Review this diff:\n\n" + $diff)}]}' |
    curl -sS --max-time 180 -o "$resp_file" -w '%{http_code}' \
      -X POST "$BASE_URL/chat/completions" \
      --config <(printf 'header = "Authorization: Bearer %s"\n' "$GROKIFIED_API_KEY") \
      -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends the full git diff to a third-party API, but at execution time it does not present a clear, explicit warning or require confirmation before transmitting potentially sensitive source code. Although the header comment documents this behavior and some secret-like file patterns are excluded, diffs can still contain credentials, proprietary logic, customer data, or secrets embedded in ordinary files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.