Back to skill

Security audit

gh-issues

Security checks for vulnerabilities and agentic risk

Overview

This skill automates GitHub fixes and PRs, but it exposes GitHub tokens and can make unattended repository and global Git changes.

Review before installing. Use only with a narrowly scoped GitHub token and a repository you are comfortable letting an agent modify. Avoid --yes, --cron, and --notify-channel unless you have an external approval process. If this has already been run, check .git/config and global Git credential settings for token-bearing remotes or changed helpers, and rotate the token if it may have appeared in logs or transcripts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:347
Finding

Untrusted GitHub Content Can Hijack Privileged Sub-Agents

Content
View full analysis
Repository: {SOURCE_REPO} Issue: #{number} Title: {title} URL: {url} Labels: {labels} Body: {body} ``` Review comments are similarly passed to an agent that is instructed to implement them: ```text {json_array_of_actionable_comments} Each comment has: - id: comment ID (for replying) - user: who left it - body: the comment text - path: file path (for inline comments) - line: line number (for inline comments) - diff_hunk: surrounding diff context (for inline comments) - source: where the comment came from (review, inline, pr_body, greptile, etc.) Follow these steps in order: ... 2. UNDERSTAND — Read ALL review comments carefully. Group them by file. Understand what each reviewer is asking for. 3. IMPLEMENT — For each comment, make the requested change: - Read the file and locate the relevant code - Make the change the reviewer requested - If the comment is vague or you disagree, still attempt a reasonable fix but note your concern - If the comment asks for something impossible or contradictory, skip it and explain why in your reply ``` ### Technical Analysis GitHub issue titles, bodies, ...[truncated 2347 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:89
Finding

GitHub Token Is Printed and Persisted in Git Remote URLs

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi ``` 2. Never embed credentials in Git remote URLs. 3. Use an ephemeral `GIT_ASKPASS` helper, a secure credential provider, or another mechanism that does not persist the token in `.git/config`. 4. Prefer short-lived GitHub App installation tokens restricted to the required repository. 5. Grant only the permissions needed to read issues and create or update the intended branches and pull requests. 6. Redact authentication headers, environment values, and credential-bearing URLs from all logs and transcripts. 7. Remove any previously persisted token URLs and rotate affected tokens. 8. If transcripts must be retained, apply automatic secret scanning and redaction before storage. 9. Avoid letting code-analysis agents read credential configuration files directly; inject narrowly scoped credentials only into a dedicated publishing component. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:415
Finding

Unvalidated Values Are Interpolated into Shell Commands and JSON Payloads

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:444
Finding

Skill Persistently Disables the User's Global Git Credential Helper

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (29)

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The sub-agent is explicitly instructed to print a prefix of GH_TOKEN for verification. Partial secret disclosure is still credential leakage: logs, transcripts, or downstream observers can capture the token fragment, aiding secret reconstruction, correlation, or validation attacks.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The review-fix sub-agent repeats the same unsafe pattern of printing part of GH_TOKEN. This duplicates the secret-leak path across another execution path, increasing exposure through logs and preserved sub-agent transcripts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill advertises fetching issues and opening PRs, but lacks a strong upfront warning that it will modify the repository, create branches, push commits, and open pull requests. Users may invoke it without appreciating the scope of autonomous write actions, especially when combined with auto-confirmation flags.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The prose states 'No gh CLI dependency' and says the skill uses curl plus the REST API exclusively, but the manifest metadata at L009 and L016-L18 declares gh as a required binary and installation target. This is an active contradiction between the skill's documentation and its declared setup requirements.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The presence of a --yes flag that skips confirmation is risky because this skill can make remote repository changes and spawn additional agents. Removing approval gates is especially dangerous when combined with issue ingestion from external, potentially attacker-controlled content.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
| --watch | false | Keep polling for new issues and PR reviews after each batch |
| --interval | 5 | Minutes between polls (only with `--watch`) |
| --dry-run | false | Fetch and display only — no sub-agents |
| --yes | false | Skip confirmation and auto-process all filtered issues |
| --reviews-only | false | Skip issue processing (Phases 2-5). Only run Phase 6 — check open PRs for review comments and address them. |
| --cron | false | Cron-safe mode: fetch issues and spawn sub-agents, exit without waiting for results. |
| --model | _(none)_ | Model to use for sub-agents (e.g. `glm-5`, `zai/glm-5`). If not specified, uses the agent's default model. |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill exposes a flag that can send PR summaries to an external Telegram channel without a clear upfront warning in the user-facing description. This undermines informed consent and increases the risk of unintentional disclosure of repository activity, issue titles, or PR links to third parties.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

Forcing --yes automatically when --cron is set creates unattended autonomous code modification and PR creation with no interactive review. Because GitHub issues and review comments are external inputs, this materially increases the risk of attacker-influenced automated changes being pushed to repositories.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
**If `--cron` is set:**

- Force `--yes` (skip confirmation)
- If `--reviews-only` is also set, run token resolution then jump to Phase 6 (cron review mode)
- Otherwise, proceed normally through Phases 2-5 with cron-mode behavior active

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to read GitHub credentials directly from local config files outside the declared environment-variable flow, expanding the secret-access surface and normalizing filesystem credential harvesting. Because those values are then used by orchestrator and spawned sub-agents, a prompt-injection or logic flaw elsewhere could turn this into credential exfiltration or misuse at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill tells the agent to access local configuration files to retrieve GH_TOKEN without clearly warning the user that local credentials will be read. Accessing stored secrets from disk is sensitive behavior, and hiding it inside operational steps weakens transparency and increases the chance of unauthorized credential use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 238)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 254)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 465)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 610)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 627)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 634)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 641)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 652)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 662)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 803)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 810)May include surrounding context.

text
curl -s -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github+json" \
  "https://api.github.com/repos/{SOURCE_REPO}/issues?per_page={limit}&state={state}&{query_params}"

Where {query_params} is built from:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
81% confidence
Finding

Auto-processing all listed issues without confirmation increases the skill's autonomy over code changes, branch creation, pushes, and PR submissions. In a prompt-driven environment, this reduces a key human approval checkpoint and makes accidental or malicious issue-triggered modifications more likely.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
If `--yes` is active:

- Display the table for visibility
- Auto-process ALL listed issues without asking for confirmation
- Proceed directly to Phase 4

Otherwise:

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
If output is non-empty, warn the user:

   > "Working tree has uncommitted changes. Sub-agents will create branches from HEAD — uncommitted changes will NOT be included. Continue?"
   > Wait for confirmation. If declined, stop.

2. **Record base branch:**

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

  1. Verify GH_TOKEN validity:

    text
    curl -s -o /dev/null -w "%{http_code}" -H "Authorization: Bearer $GH_TOKEN" https://api.github.com/user
    

    If HTTP status is not 200, stop with:

Static analysis

No suspicious patterns detected.