Security audit
AtomGit
Security checks for vulnerabilities and agentic risk
Overview
This is a disclosed AtomGit helper that requires a token but keeps setup manual and asks for confirmation before risky changes.
Install only if you intend to use AtomGit MCP. Review the referenced MCP server yourself, store ATOMGIT_TOKEN in your client or secret store, start with the smallest token scope needed, and require explicit confirmation for repository writes, membership or permission changes, enterprise administration, webhook changes, and dangerous-tool use.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
