Back to skill

Security audit

untrusted-code-safety

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent untrusted-code safety guide, but it tells the agent to make persistent global Git and npm configuration changes that can affect unrelated work.

Review this skill before installing. Its sandboxing advice is generally defensive, but the global Git and npm configuration commands should be replaced with per-command, repository-local, or temporary-HOME equivalents, with explicit restoration if any persistent setting is changed.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Warning
Location
SKILL.md:79
Finding

Persistent Global Disabling of Git Hooks

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:79
Vulnerability Type: Persistent modification of user-wide Git configuration
Risk Level: Medium

Vulnerable snippet:

bash
npm config set ignore-scripts true
git config --global core.hooksPath /dev/null

Technical Analysis

The Skill instructs the agent to execute git config --global core.hooksPath /dev/null while preparing to inspect untrusted code. The --global option modifies the user's persistent Git configuration rather than limiting the setting to the temporary sandbox or the repository under review.

Redirecting core.hooksPath to /dev/null disables Git hooks for unrelated repositories and future Git operations. The document provides no corresponding step to preserve and restore the previous value. This also conflicts with the Skill's declared boundary that untrusted-code work should remain inside /tmp: the command modifies configuration in the user's home directory.

The behavior is presented as defensive hardening, and there is no evidence that the author intends to install attacker-controlled logic. The project is therefore classified as suspicious rather than malicious.

Attack Path

  1. A user invokes the Skill to review or run untrusted code.
  2. The agent follows the “Defang before you sandbox” instructions.
  3. The agent runs git config --global core.hooksPath /dev/null.
  4. Git writes the setting to the user's global configuration outside the temporary workspace.
  5. Subsequent Git operations in unrelated repositories no longer execute their configured hooks.
  6. The altered behavior persists after the review because the Skill does not restore the prior configuration.

Impact Assessment

The operation uses the current user's privileges and affects Git operations across that user's repositories. Legitimate pre-commit checks, policy enforcement, validation, signing workflows, secret scanning, and other hook-based cont ...[truncated 280 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not modify the user's global Git configuration.
  • Apply the override to individual commands, for example:
    bash
    git -c core.hooksPath=/dev/null <subcommand>
    
  • Alternatively, run Git with a temporary HOME and isolated global configuration located inside the sandbox.
  • If repository-local configuration is appropriate, use a setting scoped only to the disposable clone.
  • If a persistent change is unavoidable, require explicit user confirmation, record the previous value, and restore it reliably on every exit path.
  • Apply equivalent isolation to npm config set ignore-scripts true so that the Skill does not persistently alter unrelated user workflows.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says to trigger when the user says specific phrases, but also broadly on any 'suspicion of malicious, harmful, deceptive, cheating, or stealing behavior.' That condition is subjective and expansive, with no clear scope limits or exclusion examples, increasing the chance of accidental activation outside the intended untrusted-code context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.