Back to skill

Security audit

Fleet PR Agent

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does the advertised GitHub PR triage, but an included shell script has a real command-execution weakness if run with attacker-controlled environment variables.

Review before installing or running in automation. Prefer the documented Python script, avoid running scripts with untrusted environment variables, and require integer validation for FLEET_PR_STALE_DAYS, FLEET_PR_CI_WEIGHT, and FLEET_PR_MAX_PRS before using the Bash helper.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/triage.sh:94
Finding

Command Execution Through Unvalidated Bash Arithmetic Input

Content
View full analysis
Remediation
View remediation
&2 exit 2 fi } validate_uint "FLEET_PR_STALE_DAYS" "$STALE_DAYS" validate_uint "FLEET_PR_CI_WEIGHT" "$CI_WEIGHT" validate_uint "FLEET_PR_MAX_PRS" "$MAX_PRS" ``` After syntax validation, enforce sensible bounds to prevent denial-of-service or unintended behavior: ```bash if (( STALE_DAYS > 3650 )); then echo "Error: FLEET_PR_STALE_DAYS is outside the permitted range." >&2 exit 2 fi if (( MAX_PRS < 1 || MAX_PRS > 1000 )); then echo "Error: FLEET_PR_MAX_PRS must be between 1 and 1000." >&2 exit 2 fi ``` Additional hardening measures: 1. Validate configuration immediately after reading the environment and before invoking `date`, `gh`, or any arithmetic comparison. 2. Reject malformed values rather than attempting to normalize or evaluate them. 3. Apply the same numeric-validation policy to every current and future environment-controlled arithmetic value. 4. In CI and agent deployments, use an explicit environment allowlist and avoid forwarding untrusted environment variables to the Skill. 5. Add regression tests using malformed arithmetic strings and array-subscript payloads to verify that validation rejects them before PR processing begins. ]]>
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and operationalizes shell execution (gh, python3) and file output (--output report.md) but does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization ambiguity where an agent runtime may permit broader shell or file access than is necessary, increasing the chance of unintended command execution, data access, or writes beyond the intended triage workflow.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/triage.py (reported line 22)May include surrounding context.

python
cmd = ["gh", "pr", "list", "--repo", repo, "--state", "open",
           "--limit", str(MAX_PRS), "--json",
           "number,title,url,createdAt,updatedAt,isDraft,reviewDecision,statusCheckRollup,labels"]
    result = subprocess.run(cmd, capture_output=True, text=True)
    if result.returncode != 0:
        return []
    try:

Static analysis

No suspicious patterns detected.