Back to skill

Security audit

Engineering manager 1-on-1 meeting brief generator

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its stated purpose, but it handles GitHub tokens and may send private PR discussion text to an LLM when PR insights are enabled.

Install only if you are comfortable giving the skill read access to the GitHub repositories visible to the token. Prefer a fine-grained token or a narrowly scoped classic token with GITHUB_ORG set, leave PR insights off unless raw PR discussions are appropriate to send to your LLM provider, review and delete .pullstar artifacts when they may contain private data, and use an isolated Python environment with pinned dependencies where possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
prompt_builder.py:202
Finding

Untrusted GitHub Discussion Content Is Inserted Directly into the LLM Prompt

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Note
Location
scripts/agent_finalize_1on1.py:150
Finding

Mandatory Finalization Path Emits Unrelated Promotional Content and an External Link

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:37
Finding

Installation Instructions Use Unpinned Third-Party Dependencies

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

This description materially understates operational capability by framing the flow as a simple five-tool deterministic process while the documented behavior includes potentially unbounded GitHub API access, local credential/file access, network calls, and optional extraction of PR discussion text for LLM submission. That mismatch can cause operators to grant or approve the skill with an incomplete understanding of its actual data access and exfiltration surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This description materially understates operational capability by framing the flow as a simple five-tool deterministic process while the documented behavior includes potentially unbounded GitHub API access, local credential/file access, network calls, and optional extraction of PR discussion text for LLM submission. That mismatch can cause operators to grant or approve the skill with an incomplete understanding of its actual data access and exfiltration surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This description materially understates operational capability by framing the flow as a simple five-tool deterministic process while the documented behavior includes potentially unbounded GitHub API access, local credential/file access, network calls, and optional extraction of PR discussion text for LLM submission. That mismatch can cause operators to grant or approve the skill with an incomplete understanding of its actual data access and exfiltration surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This description materially understates operational capability by framing the flow as a simple five-tool deterministic process while the documented behavior includes potentially unbounded GitHub API access, local credential/file access, network calls, and optional extraction of PR discussion text for LLM submission. That mismatch can cause operators to grant or approve the skill with an incomplete understanding of its actual data access and exfiltration surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

This description materially understates operational capability by framing the flow as a simple five-tool deterministic process while the documented behavior includes potentially unbounded GitHub API access, local credential/file access, network calls, and optional extraction of PR discussion text for LLM submission. That mismatch can cause operators to grant or approve the skill with an incomplete understanding of its actual data access and exfiltration surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This description materially understates operational capability by framing the flow as a simple five-tool deterministic process while the documented behavior includes potentially unbounded GitHub API access, local credential/file access, network calls, and optional extraction of PR discussion text for LLM submission. That mismatch can cause operators to grant or approve the skill with an incomplete understanding of its actual data access and exfiltration surface.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill is designed to retrieve a GitHub personal access token from CLI args, environment variables, local credential files, or a .env file, then use it for GitHub API access. Handling credentials in multiple local sources increases secret exposure risk, and the recommended classic PAT with broad repo scope amplifies impact if the skill, surrounding agent, or local environment is compromised.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
- Python 3.11+
- Install dependencies: `pip install PyGithub python-dotenv requests`
- A GitHub personal access token (see Security section below)

---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ingest.py (reported line 44)May include surrounding context.

python
# Default socket timeout for all network operations (GitHub API calls)
socket.setdefaulttimeout(60)  # 60 seconds per API call max

# Load .env from repo root regardless of where the script is invoked from
load_dotenv(Path(__file__).parent.parent / ".env")

# ---------------------------------------------------------------------------

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ingest.py (reported line 79)May include surrounding context.

python
# Default socket timeout for all network operations (GitHub API calls)
socket.setdefaulttimeout(60)  # 60 seconds per API call max

# Load .env from repo root regardless of where the script is invoked from
load_dotenv(Path(__file__).parent.parent / ".env")

# ---------------------------------------------------------------------------

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ingest.py (reported line 382)May include surrounding context.

python
# Default socket timeout for all network operations (GitHub API calls)
socket.setdefaulttimeout(60)  # 60 seconds per API call max

# Load .env from repo root regardless of where the script is invoked from
load_dotenv(Path(__file__).parent.parent / ".env")

# ---------------------------------------------------------------------------

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ingest.py (reported line 426)May include surrounding context.

python
# Default socket timeout for all network operations (GitHub API calls)
socket.setdefaulttimeout(60)  # 60 seconds per API call max

# Load .env from repo root regardless of where the script is invoked from
load_dotenv(Path(__file__).parent.parent / ".env")

# ---------------------------------------------------------------------------

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ingest.py (reported line 438)May include surrounding context.

python
# Default socket timeout for all network operations (GitHub API calls)
socket.setdefaulttimeout(60)  # 60 seconds per API call max

# Load .env from repo root regardless of where the script is invoked from
load_dotenv(Path(__file__).parent.parent / ".env")

# ---------------------------------------------------------------------------

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agent_finalize_1on1.py (reported line 44)May include surrounding context.

python
from dotenv import load_dotenv

load_dotenv(Path(__file__).parent.parent / ".env")


# ---------------------------------------------------------------------------

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agent_prepare_1on1.py (reported line 29)May include surrounding context.

python
from dotenv import load_dotenv

load_dotenv(Path(__file__).parent.parent / ".env")


# ---------------------------------------------------------------------------

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ingest.py (reported line 45)May include surrounding context.

python
from dotenv import load_dotenv

load_dotenv(Path(__file__).parent.parent / ".env")


# ---------------------------------------------------------------------------

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ingest.py (reported line 52)May include surrounding context.

python
from dotenv import load_dotenv

load_dotenv(Path(__file__).parent.parent / ".env")


# ---------------------------------------------------------------------------

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/score.py (reported line 20)May include surrounding context.

python
from dotenv import load_dotenv

load_dotenv(Path(__file__).parent.parent / ".env")


# ---------------------------------------------------------------------------

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill instructs the agent to use shell execution, file reads/writes, environment-based secret resolution, and network access to GitHub and an LLM provider, but it does not declare any explicit tool scope such as allowed-tools or permissions. That omission weakens least-privilege controls and makes it harder for a host system to constrain what the skill may access, especially since the markdown itself directs the agent to run commands and handle sensitive artifacts.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code intentionally packages raw PR review and comment excerpts into the LLM prompt, which means untrusted natural-language content from GitHub becomes model input and later part of a persisted payload. This increases risk of sensitive data leakage, unintended disclosure of internal discussions, and prompt-level influence from adversarial or manipulative comment text embedded in the source material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code persists the full LLM input payload to disk, and that payload can include raw PR review and comment text assembled earlier from GitHub activity. Even if this is intended for debugging or reproducibility, it creates a local data exposure channel: sensitive or user-provided text may be stored in plaintext artifacts, retained longer than expected, and accessed by other local users, tools, or later pipeline stages.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a fully deterministic pipeline with 5 tool calls and zero sub-agent spawns. However, the module docstring defines an agent flow where this script prepares artifacts, then instructs an agent to perform the LLM call and run a separate finalization step, which is materially broader than a purely deterministic no-sub-agent pipeline.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code uses subprocess.run to invoke ingest.py, score.py, and agent_prepare_1on1.py. For a skill whose stated purpose is generating a 1-on-1 brief from GitHub activity, spawning local processes is not justified by the manifest description and introduces a capability beyond the stated semantic scope.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · run_brief.py (reported line 29)May include surrounding context.

python
def _run(cmd: list[str]) -> None:
    """Run a subprocess, inheriting stdout/stderr. Exit on failure."""
    result = subprocess.run(cmd)
    if result.returncode != 0:
        sys.exit(result.returncode)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a 'fully deterministic pipeline — 5 tool calls, zero sub-agent spawns,' but this script explicitly consumes '.pullstar/llm_output_{login}.json' produced by an agent and even permits raw plain-text model output copied from a chat interface. That behavior introduces nondeterministic LLM-generated content into the pipeline, which materially conflicts with the manifest's determinism claim.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

For a skill whose stated purpose is generating a 1-on-1 brief from GitHub activity, directly loading a project .env file and a user-scoped ~/.pullstar/credentials file is an additional secret-access capability. While a GitHub token is expected, the broader credential-harvesting behavior from multiple filesystem locations is not declared in the manifest and exceeds the minimal capability implied by the skill description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.