Back to skill

Security audit

GitHub Repo Teardown

Security checks for vulnerabilities and agentic risk

Overview

This skill creates public GitHub repository teardown reports and has no hidden code, persistence, credential access, or destructive behavior.

Install this if you want detailed public GitHub repository teardown reports. Be aware that short prompts containing a GitHub link may trigger a fairly extensive research-and-report workflow, so use explicit wording when you only want a brief identification or simple summary.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is configured to trigger on very broad, low-friction signals such as a dropped GitHub link or generic phrases like 'what is this?', which can cause unintended activation outside clearly scoped teardown requests. This increases the chance of misrouting user intent, unnecessary external fetching of third-party content, and over-collection of data for requests that did not actually ask for deep analysis.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The 'When to Trigger' guidance lacks negative conditions and disambiguation rules, so the skill may activate for many neighboring request types that mention a repo without actually wanting a full teardown. In context, this is risky because the skill's workflow instructs extensive web fetching and synthesis, which can waste resources, surprise users, and broaden exposure to untrusted external content unnecessarily.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.