Back to skill

Security audit

code-reviewer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a Go code-review guide, but it also directs agents to inspect fixed company repositories, named personnel, and an external dashboard, so it needs review before install.

Install only if you explicitly want both Go code review and internal team-effectiveness analytics. Before use, remove or replace the hard-coded repository paths, contributor names, fixed branch, external dashboard URL, and token-based API guidance; require explicit approval for any additional repository, employee metric, or external service access.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
rules/team-effectiveness-metrics.md:15
Finding

Hard-coded access scope includes unrelated local organizational repositories and employee activity

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
rules/team-effectiveness-metrics.md:619
Finding

Instruction to access a fixed organization-specific external dashboard without authorization controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Unvalidated Output Injection

High
Category
Output Handling
Confidence
65% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · rules/security-xss-prevention.md (reported line 29)May include surrounding context.

md
// React - dangerous!
function UserProfile({ user }) {
  return (
    <div dangerouslySetInnerHTML={{ __html: user.bio }} />
  );
}

Unvalidated Output Injection

High
Category
Output Handling
Confidence
65% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · rules/security-xss-prevention.md (reported line 61)May include surrounding context.

md
// React - dangerous!
function UserProfile({ user }) {
  return (
    <div dangerouslySetInnerHTML={{ __html: user.bio }} />
  );
}

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file explicitly lists named contributors and sets up evaluation of individual contribution patterns, which enables profiling of employees rather than review of code artifacts. In a code-review skill, this creates privacy and misuse risk because the collected outputs can be repurposed for performance monitoring, targeting, or unfair personnel decisions.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · rules/team-effectiveness-metrics.md (reported line 425)May include surrounding context.

md
| timeRange.start | string | 开始时间 |
| timeRange.end | string | 结束时间 |
** 使用说明 **
- 需要有效的访问令牌(Access Token)
- 时间参数为空时默认统计最近30天数据
- repositoryId参数用于筛选特定代码仓库的数据

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section materially expands the skill from Go code review into employee surveillance and organizational profiling by tracking AI-usage behavior, contribution patterns, and productivity-style metrics. In the context of a code-review skill, this is over-privileged scope creep that can enable invasive monitoring unrelated to the stated purpose and may drive collection of sensitive personnel data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains natural-language instructional content in Chinese alongside English, such as the comments at L051 and L075, but it does not state that the skill is intended to operate bilingually or within a Chinese-specific context. Because SQP-3 applies to all file types and covers language/locale policy violations, forcing or assuming a language without user opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Several later sections also embed Chinese natural-language comments, including L103, L120, L133, L172, L197, L238, L299, L310, L331, and L341, while the document otherwise presents itself as a general code review guide. The file does not explain this language constraint or offer users a choice, so the mixed-language requirement can violate the stated language/locale policy rule.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation triggers are so broad that the skill may activate for generic 'code review', 'security vulnerabilities', or 'performance issues' requests without confirming the target is Go. In an agentic environment, this can cause inappropriate routing, irrelevant or misleading analysis, and over-application of the skill to contexts it was not designed for, which is dangerous for security workflows that depend on precise tool selection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a Go code review skill focused on security, performance, best practices, and test coverage. The added 'Team-Effectiveness' section introduces weekly team activity measurement over commits and review activity, which is a distinct analytics function rather than code review behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document is primarily written in English but introduces a Chinese-titled section and linked rule, which can impose a language/locale constraint on users without opt-in. No justification or alternative language option is provided for this mixed-language requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document title, instructions, examples, and operational guidance are all presented in Chinese, which effectively forces a specific language for users of this skill. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific; neither is stated here.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This instruction directs the agent to retrieve data from an external web dashboard unrelated to narrow Go code-review functionality. That increases attack surface and privacy risk by encouraging network access and ingestion of external telemetry without clear necessity, validation, or scoping controls.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

At L036, the document states that -covermode=count enables branch coverage analysis, and later sections at L060-L066 define branch coverage thresholds as a required metric. However, the provided go test command generates Go coverage profiles that track statement execution counts, not true branch coverage, so the documentation materially overstates what the process measures.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file repeatedly frames itself as a Go-specific review skill, but 'Add Type Hints' is terminology associated with dynamically typed languages, not Go. This is not merely incomplete wording: it instructs reviewers to look for a concept that does not apply as stated to Go code.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example output presents 'Missing Type Hints' as a valid Go review issue, but Go uses static type declarations in signatures rather than optional type hints. This actively conflicts with the document's stated purpose as a Go reviewer and could mislead the agent into applying non-Go review criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

L018 says the command is required 'to generate coverage data', which suggests a narrow purpose, but the command at L021-L026 also emits full JSON test results into test-report.json. This is not merely omitted detail elsewhere: the wording frames the command as only for coverage generation while it also performs broader test result collection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L081 contains the standalone Chinese term "运行", and a similar instance appears again at L098, in an otherwise English-language skill document. This introduces a locale/language inconsistency without user opt-in or documentation that the skill is intended for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L098 again includes the standalone Chinese term "运行" in an otherwise English document. Requiring or inserting a specific language without opt-in can violate language/locale policy expectations for general-purpose skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.