Back to skill

Security audit

GitHub Workflow

Security checks for vulnerabilities and agentic risk

Overview

The skill is not malicious, but it broadly forces a GitHub workflow onto general coding tasks and may create or change repository artifacts unless users keep tight control.

Install only if you want an agent to follow a strict GitHub-centered process. Before using it, require explicit approval for every branch, commit, issue, pull request, merge, release, secret, workflow, branch-protection change, and work-log write, and avoid enabling it globally for ordinary coding tasks.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:10
Finding

Global Agent Workflow Hijacking Through Mandatory Skill Directives

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10-16 and 30-39
Vulnerability Type: Global instruction and workflow hijacking
Risk Level: High

Vulnerable Code Snippet

markdown
## Agent Directives

These are mandatory behavioral rules. Follow them in every situation involving code, projects, or tasks.

### On skill installation
When this skill is first loaded, introduce it to the user:
- Explain that all project work will now follow a professional GitHub workflow
- Mention: branching strategy, work logs, CI checks, semantic versioning, security rules
- Ask: "Do you have an existing project, or are we starting a new one?"
markdown
### On every task
- Assess task scale first (see Task scale table in Agent Workflow).
- Tiny tasks: branch → commit → quick-log → PR → confirm with user → merge.
- Normal/significant tasks: Issue and work log are mandatory before branching.
- Never commit directly to `main` or `develop`.
- Never skip the pre-PR checklist on normal/significant tasks.
- Never expose tokens, secrets, or credentials in any command or output.
- If something is irreversible (delete, merge, release, force push) — **always confirm with the user first**.

### On using this skill
- This file (SKILL.md) is always in context — use it for workflow, branching, work log rules.
- Reference files are loaded **on demand only** — read them when the task requires it, not upfront.
- Work log is not optional — it is part of every task from start to finish.
- When in doubt about a GitHub operation — check the relevant reference file before acting.

Technical Analysis

The skill declares its behavioral rules mandatory for every code, project, or task rather than limiting them to explicit GitHub workflow requests. Loading the skill can therefore alter the agent's current objective by forcing an introductory interaction, task classification, branching, issue creation, pull-r ...[truncated 1897 chars]

Remediation
View remediation

Remediation Suggestions

  1. Limit activation to explicit user requests involving GitHub repository workflow operations.
  2. Replace global language such as “mandatory,” “every situation,” and “every task” with narrowly scoped guidance that applies only after the user opts into the workflow.
  3. Do not automatically redirect the conversation when the skill loads. Present workflow assistance only when relevant to the current request.
  4. Require explicit user approval before creating branches, issues, commits, pull requests, work logs, or other repository artifacts.
  5. Make work-log creation optional and disclose its path, contents, retention behavior, and purpose before writing it.
  6. Preserve the agent's higher-priority safety rules and the user's current objective by explicitly stating that skill guidance must not override either.
  7. Add a scope guard such as: “Use these procedures only when the user explicitly requests GitHub workflow management; otherwise, do not modify repositories or create workflow artifacts.”
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

md
| CI runs, GitHub Actions | `references/ci-actions.md` |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger scope is extremely broad, covering common terms like git, repo, commit, branch, issue, and CI, which are likely to appear in many normal coding conversations. In an agent skill system, overbroad triggers can cause the skill to activate unexpectedly and impose heavyweight behaviors or side-effecting workflow instructions in contexts where the user did not ask for them.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill imposes mandatory behavioral rules for every situation involving code, projects, or tasks, without obtaining user opt-in or checking whether the workflow fits the current environment. In an agent setting, this can override user intent, force unnecessary repository operations, and increase the chance of unwanted writes, authentication prompts, or workflow lock-in across unrelated tasks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that all write operations require explicit user confirmation, but elsewhere prescribes write actions such as creating issues, branches, draft PRs, work logs, stashes, and local file modifications as part of the default workflow without always requiring confirmation. In an agentic context, this inconsistency can cause the agent to perform repository or filesystem changes the user did not explicitly approve, weakening user control over side effects.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The 'On every task' section says normal/significant tasks require an issue and work log before branching, implying PR workflow is expected, while the Task scale table later says for normal tasks 'PR only if risky'. The later normal/significant workflow then again includes opening and merging a PR as standard behavior. These instructions contradict each other and may cause inconsistent agent behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.