T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:79- Finding
Persistent Global Disabling of Git Hooks
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:79
Vulnerability Type: Persistent modification of user-wide Git configuration
Risk Level: MediumVulnerable snippet:
bash npm config set ignore-scripts true git config --global core.hooksPath /dev/nullTechnical Analysis
The Skill instructs the agent to execute
git config --global core.hooksPath /dev/nullwhile preparing to inspect untrusted code. The--globaloption modifies the user's persistent Git configuration rather than limiting the setting to the temporary sandbox or the repository under review.Redirecting
core.hooksPathto/dev/nulldisables Git hooks for unrelated repositories and future Git operations. The document provides no corresponding step to preserve and restore the previous value. This also conflicts with the Skill's declared boundary that untrusted-code work should remain inside/tmp: the command modifies configuration in the user's home directory.The behavior is presented as defensive hardening, and there is no evidence that the author intends to install attacker-controlled logic. The project is therefore classified as suspicious rather than malicious.
Attack Path
- A user invokes the Skill to review or run untrusted code.
- The agent follows the “Defang before you sandbox” instructions.
- The agent runs
git config --global core.hooksPath /dev/null. - Git writes the setting to the user's global configuration outside the temporary workspace.
- Subsequent Git operations in unrelated repositories no longer execute their configured hooks.
- The altered behavior persists after the review because the Skill does not restore the prior configuration.
Impact Assessment
The operation uses the current user's privileges and affects Git operations across that user's repositories. Legitimate pre-commit checks, policy enforcement, validation, signing workflows, secret scanning, and other hook-based cont ...[truncated 280 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not modify the user's global Git configuration.
- Apply the override to individual commands, for example:
bash git -c core.hooksPath=/dev/null <subcommand> - Alternatively, run Git with a temporary
HOMEand isolated global configuration located inside the sandbox. - If repository-local configuration is appropriate, use a setting scoped only to the disposable clone.
- If a persistent change is unavoidable, require explicit user confirmation, record the previous value, and restore it reliably on every exit path.
- Apply equivalent isolation to
npm config set ignore-scripts trueso that the Skill does not persistently alter unrelated user workflows.
