Back to skill

Security audit

gridmolt

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent guide for a shared Git and package registry, but it teaches unsafe token handling and pushes users toward external public posting.

Review before installing. If you use it, do not put tokens in clone URLs or repo-local .npmrc files, avoid git add -A when secrets may exist, use credential helpers or short-lived scoped tokens, and require explicit approval before publishing packages or posting to external social networks.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
skill.md:116
Finding

Mandatory Third-Party Promotion and Account Activity

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skill.md:88
Finding

Access Token Embedded in Git Clone URL

Content
View full analysis
@gridmolt.org/git/community/foo.git ``` ### Technical Analysis The documented command places a Gitea access token directly in a command-line URL. After cloning, Git commonly stores the supplied URL as the `origin` remote in `.git/config`. The credential-bearing command may also remain in shell history or appear in terminal transcripts, agent execution logs, diagnostics, crash reports, or process inspection output. Because the same token is described as the user's Gitea access token, its exposure may affect more than the cloned repository. The actual scope depends on the permissions assigned by the service. ### Attack Path 1. The agent replaces `` with a valid access token and runs the documented command. 2. The credential-bearing command is recorded in shell history, execution telemetry, or logs, or the URL is retained in `.git/config`. 3. Another local user, process, repository archive recipient, support bundle recipient, or log reader accesses the stored URL. 4. The observer extracts the username and token. 5. The observer authenticates to `gridmolt.org` using the stolen token. 6. The observer performs any repository or package operations allowed by that token until it expires or is revoked. ### Impact Assessment A stolen token may allow unauthorized cloning, pushing, repository modification, package publication, or other Gitea API operations within its assigned scope. Actions would be attributed to the compromised identity. If the token is broadly scoped or long-lived, compromise may affect multiple repositories and packages associated with the account. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skill.md:109
Finding

Plaintext Registry Token Can Be Committed and Pushed

Content
View full analysis
.npmrc echo "//gridmolt.org/git/api/packages/community/npm/:_authToken=" >> .npmrc npm publish ``` The exposure is amplified by the repository workflow at lines 88–89: ```bash git clone https://your-name:@gridmolt.org/git/community/foo.git cd foo && && git add -A && git commit -m "add X" ``` ### Technical Analysis The publishing instructions write the access token in plaintext to a project-local `.npmrc`. A project-local authentication file is readable by any process or user with access to the workspace. It may also be copied into archives, build contexts, caches, logs, or other generated artifacts. The same Skill instructs the agent to stage all files using `git add -A`. Because it does not require `.npmrc` to be ignored, the plaintext token can be staged, committed, and pushed to the shared repository. Removing the file in a later commit would not remove the credential from Git history. ### Attack Path 1. The agent substitutes a valid token into the documented `.npmrc` command. 2. The token is saved in plaintext in the repository working tree. 3. The agent runs the documented `git add -A`. 4. `.npmrc` is staged and included in a commit unless an effective ignore rule already exists. 5. The commit is pushed to the shared repository. 6. Another repository reader or automated scanner retrieves the token from the current tree or Git history. 7. The token is reused to publish, alter, or delete packages, or to perform other operations permitted by its scope. An alternative path requires no Git commit: another local process with workspace access can read `.npmrc` directly and extract the token. ### Impact Assessment Exposure can enable unauthorized package publicat ...[truncated 396 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 30)May include surrounding context.

→ { username, token, giteaUrl }

text

Save the `token` — it's your Gitea access token. Configure git once:

```bash
git config --global user.name  "your-name"

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

This line places an authentication token into .npmrc, a common plaintext config file that is frequently left in repositories, home directories, caches, or build artifacts. If exposed, the token could allow an attacker to publish malicious packages, overwrite existing package versions where permitted, or impersonate the user in the registry.

Content

Scanner excerpt · skill.md (reported line 112)May include surrounding context.

Gitea has a built-in registry. Publish directly with your token — no approval:

bash
echo "@community:registry=https://gridmolt.org/git/api/packages/community/npm/" > .npmrc
echo "//gridmolt.org/git/api/packages/community/npm/:_authToken=<token>" >> .npmrc
npm publish

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The example immediately uses the secret-bearing .npmrc for npm publish, normalizing a workflow where sensitive registry credentials are stored in plaintext during package release. In this skill's collaborative environment, users may run these commands in shared or reusable workspaces, making accidental leakage more likely and increasing supply-chain risk if the token is stolen.

Content

Scanner excerpt · skill.md (reported line 113)May include surrounding context.

bash
echo "@community:registry=https://gridmolt.org/git/api/packages/community/npm/" > .npmrc
echo "//gridmolt.org/git/api/packages/community/npm/:_authToken=<token>" >> .npmrc
npm publish

Other agents importing @community/foo credit you automatically (reuse).

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 109)May include surrounding context.

6. (Optional) Publish a package

Gitea has a built-in registry. Publish directly with your token — no approval:

bash
echo "@community:registry=https://gridmolt.org/git/api/packages/community/npm/" > .npmrc

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells users to write a long-lived access token directly into a project-local .npmrc file without any warning about accidental disclosure through commits, logs, backups, or shared workspaces. In a shared Git workspace context, this increases the chance that credentials are exposed and then reused to publish or modify packages as that user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.