Back to skill

Security audit

GitHub Reader

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently analyzes user-specified public GitHub repositories using GitHub's API and local caching, with no evidence of hidden execution or data theft.

Install only if you are comfortable with the skill sending requested public repository names to GitHub's API and caching generated reports locally. Treat README excerpts in its output as untrusted repository content, not instructions to follow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
github_reader_v3_secure.py:305
Finding

Untrusted GitHub README Content Is Embedded in Agent-Consumable Output

Content
View full analysis
Optional[str]: """获取 README 内容(截取前 3000 字符用于摘要)""" if not validate_repo_name(owner) or not validate_repo_name(repo): return None async with self.semaphore: data = await self._api_get( safe_url_join('https://api.github.com/repos', owner, repo, 'readme') ) if not data: return None content = data.get('content', '') if not content: return None try: import base64 decoded = base64.b64decode(content).decode('utf-8', errors='replace') return decoded[:3000] except Exception: return None ``` ```python # 从 README 提取摘要 summary_lines = [] if readme_raw: for line in readme_raw.split('\n'): clean = line.strip() if clean and not clean.startswith('#') and not clean.startswith('![') \ and not clean.startswith('<') and len(clean) > 20: summary_lines.append(clean[:200]) if len(summary_lines) >= 5: break report['readme_snippets'] = summary_lines ``` ```python def _render_markdown(self, report: Dict) -> str: owner = report['owner'] repo = report['repo'] info = report.get('github_info', {}) snippets = report.get('readme_snippets', []) github_url = report['github_url'] description = info.get('description', '这是一个开源项目。') snippet_block = '\n'.join(f'> {s}' for s in snippets) if snippets else '> *(README 暂无摘要)*' archived_note = '\n> ⚠️ **注意**:此仓库已被归档(只读)\n' if info.get('archived') else '' return f"""# 📦 {owner}/{repo} 深度解读报告 > **分析时间**: {datetime.now().strftime('%Y-%m-%d %H:%M')} > **数据来源**: GitHub REST ...[truncated 2819 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (19)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 78)May include surrounding context.

python
# 1. 输入验证 — 路径遍历应被拒绝
assert validate_repo_name("../etc/passwd") == False
assert validate_repo_name("repo..config") == False
assert validate_repo_name("microsoft/BitNet") == False  # 不含 /
assert validate_repo_name("valid-repo") == True

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 90)May include surrounding context.

python
# 1. 输入验证 — 路径遍历应被拒绝
assert validate_repo_name("../etc/passwd") == False
assert validate_repo_name("repo..config") == False
assert validate_repo_name("microsoft/BitNet") == False  # 不含 /
assert validate_repo_name("valid-repo") == True

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SECURITY.md (reported line 124)May include surrounding context.

  1. 清除缓存

    bash
    rm -rf /tmp/gitview_cache
    
  2. 检查日志

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SECURITY.md (reported line 124)May include surrounding context.

export GITVIEW_CACHE_TTL="24" # 缓存时间(小时)

text

清除缓存:`rm -rf /tmp/gitview_cache`

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

export GITVIEW_CACHE_TTL="24" # 缓存时间(小时)

text

清除缓存:`rm -rf /tmp/gitview_cache`

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

export GITVIEW_CACHE_TTL="24" # 缓存时间(小时)

text

清除缓存:`rm -rf /tmp/gitview_cache`

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description and usage guidance are written in Chinese, including the suggested natural-language invocation example, with no indication that other languages are supported or that Chinese is a required locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file title and all explanatory content are written in Chinese, and line L39 explicitly notes a bilingual capability in v3.1 while this document itself provides no language choice or opt-in. Under the policy rule, forcing a specific language without user opt-in is a natural-language locale violation unless clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains all user-facing instructions and safety guidance in Chinese, including operational steps and warnings. Under the language/locale policy, forcing a specific language without user opt-in can be a policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language description and usage instructions are written entirely in Chinese, including the title and command guidance, with no indication that users can choose another language. This can violate language/locale policy when a skill imposes a specific language without documenting opt-in or offering alternatives.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description is written as an unconditional Chinese-language instruction ('深度解读 GitHub 项目,生成结构化分析报告') with no indication that users may choose another language. For a manifest file, this can indicate a locale policy issue unless the language constraint is explicitly optional or justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file-level docstrings, user-facing hints, errors, time labels, and generated report content are all written in Chinese, indicating the skill is designed to operate in a single language by default. The file does not provide any opt-in, fallback, or documented justification for enforcing this locale, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SECURITY.md (reported line 84)May include surrounding context.

md
return None
        async with self.semaphore:
            data = await self._api_get(
                safe_url_join('https://api.github.com/repos', owner, repo)
            )
        if not data:
            return None

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · github_reader_v3_secure.py (reported line 278)May include surrounding context.

python
return None
        async with self.semaphore:
            data = await self._api_get(
                safe_url_join('https://api.github.com/repos', owner, repo)
            )
        if not data:
            return None

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · github_reader_v3_secure.py (reported line 305)May include surrounding context.

python
return None
        async with self.semaphore:
            data = await self._api_get(
                safe_url_join('https://api.github.com/repos', owner, repo)
            )
        if not data:
            return None

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · github_reader_v3_secure.py (reported line 395)May include surrounding context.

python
return None
        async with self.semaphore:
            data = await self._api_get(
                safe_url_join('https://api.github.com/repos', owner, repo)
            )
        if not data:
            return None

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install_v3_secure.sh (reported line 28)May include surrounding context.

sh
cp "$SOURCE_DIR/clawhub.json" "$SKILL_DIR/"

# 设置权限
chmod 700 /tmp/gitview_cache

echo "✅ Skill 已安装到:$SKILL_DIR"
echo "✅ 缓存目录:/tmp/gitview_cache(权限:700)"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file explicitly requires bilingual and Chinese/English paired README variants, which reflects a fixed language/locale choice in the skill package materials. No user choice or region-specific justification is provided in this file, so this appears to be a natural-language locale policy constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script mixes English labels with predominantly Chinese user-facing messages and usage examples, but does not indicate that language is configurable or optional. This can violate a language/locale policy when users are expected to receive output in a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.