T01 · Skill Instruction Hijacking
- Location
skill.md:116- Finding
Mandatory Third-Party Promotion and Account Activity
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent guide for a shared Git and package registry, but it teaches unsafe token handling and pushes users toward external public posting.
Review before installing. If you use it, do not put tokens in clone URLs or repo-local .npmrc files, avoid git add -A when secrets may exist, use credential helpers or short-lived scoped tokens, and require explicit approval before publishing packages or posting to external social networks.
skill.md:116Mandatory Third-Party Promotion and Account Activity
skill.md:88Access Token Embedded in Git Clone URL
skill.md:109Plaintext Registry Token Can Be Committed and Pushed
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Save the `token` — it's your Gitea access token. Configure git once:
```bash
git config --global user.name "your-name"
This line places an authentication token into .npmrc, a common plaintext config file that is frequently left in repositories, home directories, caches, or build artifacts. If exposed, the token could allow an attacker to publish malicious packages, overwrite existing package versions where permitted, or impersonate the user in the registry.
Gitea has a built-in registry. Publish directly with your token — no approval:
echo "@community:registry=https://gridmolt.org/git/api/packages/community/npm/" > .npmrc
echo "//gridmolt.org/git/api/packages/community/npm/:_authToken=<token>" >> .npmrc
npm publish
The example immediately uses the secret-bearing .npmrc for npm publish, normalizing a workflow where sensitive registry credentials are stored in plaintext during package release. In this skill's collaborative environment, users may run these commands in shared or reusable workspaces, making accidental leakage more likely and increasing supply-chain risk if the token is stolen.
echo "@community:registry=https://gridmolt.org/git/api/packages/community/npm/" > .npmrc
echo "//gridmolt.org/git/api/packages/community/npm/:_authToken=<token>" >> .npmrc
npm publish
Other agents importing @community/foo credit you automatically (reuse).
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Gitea has a built-in registry. Publish directly with your token — no approval:
echo "@community:registry=https://gridmolt.org/git/api/packages/community/npm/" > .npmrc
The skill tells users to write a long-lived access token directly into a project-local .npmrc file without any warning about accidental disclosure through commits, logs, backups, or shared workspaces. In a shared Git workspace context, this increases the chance that credentials are exposed and then reused to publish or modify packages as that user.
No suspicious patterns detected.