Back to skill

Security audit

Git Log Tracker (Commit Index & Query CLI)

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it claims, but it installs persistent Git hooks, aggregates commit metadata locally, includes unrelated agent policy files, and documents an unsafe remote installer command.

Install only if you want persistent local tracking of commit metadata across repositories. Review and remove the unrelated AGENTS.md/CLAUDE.md policy files, avoid the curl-to-shell uv installer, restrict permissions on ~/.commit-logs, and require explicit confirmation before global mode, bulk scan installation, delete/update, or reinstall actions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/ONBOARDING.md:240
Finding

Unverified Remote Installer Is Piped Directly into a Shell

Content
View full analysis

Vulnerability Details

File Location: references/ONBOARDING.md:240
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
curl -LsSf https://astral.sh/uv/install.sh | sh

Technical Analysis

The troubleshooting instructions download a mutable remote script and immediately pass it to sh. The script is not pinned to a specific version, saved for inspection, or verified using a cryptographic signature or trusted checksum.

Although the URL appears to belong to the legitimate uv project and HTTPS protects the connection in transit, the effective code being executed may change after this Skill has been reviewed. Compromise of the distribution server, publishing process, domain, or applicable TLS trust chain could therefore turn this instruction into arbitrary code execution.

This behavior is not necessary for the Skill's core commit-indexing functionality. Installing uv may be a prerequisite, but doing so through an unverified remote shell pipeline exceeds the minimum safe execution mechanism needed to satisfy that prerequisite.

Attack Path

  1. A user attempts to configure the Skill on a system where uv is unavailable.
  2. The Agent follows the mandatory onboarding troubleshooting instructions.
  3. curl retrieves the current response from https://astral.sh/uv/install.sh.
  4. The response is streamed directly to sh without inspection or integrity verification.
  5. If the remote distribution channel has been compromised, attacker-controlled shell commands execute with the privileges of the user running the command.
  6. Those commands can access or modify any files and credentials available to that user and may establish additional persistence.

Impact Assessment

Successful exploitation provides arbitrary command execution under the invoking user's account. The resulting scope may include:

  • Reading and modifying source repositori ...[truncated 543 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the curl | sh instruction.
  • Prefer installation through a trusted operating-system package manager or another repository with authenticated package metadata.
  • If the upstream installer must be used:
    1. Pin a specific installer release or immutable artifact.
    2. Download it to a local file without executing it.
    3. Verify a publisher signature or a SHA-256 checksum obtained through a separately authenticated channel.
    4. Allow the user to inspect the downloaded script.
    5. Request explicit confirmation before execution.
    6. Execute it without elevated privileges.
  • Document the files and configuration the installer is expected to modify.
  • In Agent instructions, require explicit user authorization before downloading or executing any external installer.

T09 · Insecure Skill Coding Practices

Warning
Location
src/config.py:44
Finding

Commit Metadata Storage Does Not Enforce Restrictive File Permissions

Content
View full analysis

Vulnerability Details

File Location: src/config.py:44-47, src/config.py:83-87, and src/db.py:31-35
Vulnerability Type: Insecure local storage permissions
Risk Level: Medium

Vulnerable Code

python
def ensure_config_exists() -> Path:
    """Ensure config directory and file exist, return config path."""
    DEFAULT_CONFIG_DIR.mkdir(parents=True, exist_ok=True)
    if not DEFAULT_CONFIG_PATH.exists():
        DEFAULT_CONFIG_PATH.write_text(get_default_config_content(), encoding="utf-8")
    return DEFAULT_CONFIG_PATH
python
def write_labels(data: dict) -> None:
    """Write labels mapping to labels.json."""
    DEFAULT_CONFIG_DIR.mkdir(parents=True, exist_ok=True)
    with open(DEFAULT_LABELS_PATH, "w", encoding="utf-8") as f:
        json.dump(data, f, indent=2, ensure_ascii=False)
python
def get_connection(db_path: Path | None = None) -> sqlite3.Connection:
    if db_path is None:
        db_path = DEFAULT_DB_PATH
    db_path.parent.mkdir(parents=True, exist_ok=True)
    conn = sqlite3.connect(str(db_path))

Technical Analysis

The Skill creates ~/.commit-logs, config.toml, labels.json, and the SQLite database without explicitly enforcing owner-only permissions. Their effective permissions therefore depend on the process umask and existing parent-directory permissions.

The SQLite database contains repository paths, author and committer email addresses, branch names, commit subjects, and complete commit bodies. The labels file also discloses normalized repository paths. This information may expose confidential project names, filesystem structure, identities, and sensitive text accidentally committed in messages.

On a multi-user system with a permissive umask or pre-existing permissive directory, another local account may be able to read these files. The issue does not independently provide remote access or privilege escalation, but it weakens co ...[truncated 1184 chars]

Remediation
View remediation

Remediation Suggestions

  • Create ~/.commit-logs with owner-only permissions (0700 on POSIX systems).
  • Create config.toml, labels.json, and index.db with mode 0600.
  • After opening existing storage, validate and correct overly broad permissions where supported.
  • Use secure low-level file creation flags, such as O_CREAT | O_EXCL with an explicit mode, where race resistance is required.
  • Write labels.json to an owner-only temporary file in the same directory, flush and synchronize it, and atomically replace the destination.
  • Avoid following unexpected symbolic links when creating or replacing sensitive storage files.
  • Document that the database contains aggregated commit metadata and should be protected as potentially confidential.
  • Add tests that run under a permissive umask and verify that the final directory and file modes remain owner-only.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (45)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file content is a project-wide testing and development policy document, not a skill for git commit logging or SQLite commit indexing as declared in the metadata. This mismatch can cause an agent to execute unrelated actions such as running tests, managing hooks, or changing commit behavior when the user only requested commit-history indexing, expanding the skill's authority and enabling prompt-scope confusion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This file is materially unrelated to the declared git commit indexing skill and instead injects a broad software-development policy, test workflow, hook behavior, and commit message rules. In an agentic environment, such scope drift is dangerous because the agent may follow these instructions while handling unrelated git-log-tracker tasks, causing unauthorized workflow changes, unexpected test execution, hook management, or behavioral override outside the skill’s stated purpose.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · AGENTS.md (reported line 237)May include surrounding context.

md
| `pre-commit` | 每次 `git commit` | 快速通道:lint + 单元测试(≤ 10s) |
| `pre-push` | 每次 `git push` | 全套:单元 + 集成 + 覆盖率校验 |

**禁止**用 `git commit --no-verify` / `git push --no-verify` 绕过,除非已修复底层问题。

hook 脚本镜像位于 `scripts/git-hooks/`,由 `init_env` 软链到 `.git/hooks/`,否则新 clone 的同事不会自动获得 hook。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CLAUDE.md (reported line 237)May include surrounding context.

md
| `pre-commit` | 每次 `git commit` | 快速通道:lint + 单元测试(≤ 10s) |
| `pre-push` | 每次 `git push` | 全套:单元 + 集成 + 覆盖率校验 |

**禁止**用 `git commit --no-verify` / `git push --no-verify` 绕过,除非已修复底层问题。

hook 脚本镜像位于 `scripts/git-hooks/`,由 `init_env` 软链到 `.git/hooks/`,否则新 clone 的同事不会自动获得 hook。

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code does not implement commit logging, SQLite storage, post-commit hook behavior, or commit history querying. Its primary function is unrelated: it validates that version numbers match across project metadata files and git tags. While it uses git, it only reads tags for version checking, not commit metadata. This is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a substantial git/SQLite utility for recording and querying commit history. The actual code chunk does not implement any of those behaviors; it is only a unit test for package version format. This is a materially different primary purpose, not merely a supporting detail of the described tool. Therefore, the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description centers on recording Git commit metadata into SQLite and exposing a CLI for commit-history operations. The supplied code does not implement or test commit indexing behavior; instead, it focuses on configuration handling and label persistence. While config support could be ancillary to the larger tool, this chunk’s actual behavior is materially different from the declared primary purpose and introduces a separate capability—repository labels stored in labels.json—that is not mentioned in the description. Therefore, this chunk does not accurately represent the declared functionality.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/ONBOARDING.md (reported line 257)May include surrounding context.

  1. 卸载旧 hook(如果之前已安装):
    bash
    # 如果之前使用 scripts/ 方式安装
    rm ~/.commit-logs/hook.py ~/.commit-logs/db.py ~/.commit-logs/install.py ~/.commit-logs/query.py ~/.commit-logs/setup_global.py
    rm -rf ~/.commit-logs/__pycache__
    

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/ONBOARDING.md (reported line 258)May include surrounding context.

bash
   # 如果之前使用 scripts/ 方式安装
   rm ~/.commit-logs/hook.py ~/.commit-logs/db.py ~/.commit-logs/install.py ~/.commit-logs/query.py ~/.commit-logs/setup_global.py
   rm -rf ~/.commit-logs/__pycache__
  1. 重新安装 hook(使用新 CLI):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/ONBOARDING.md (reported line 258)May include surrounding context.

bash
   # 如果之前使用 scripts/ 方式安装
   rm ~/.commit-logs/hook.py ~/.commit-logs/db.py ~/.commit-logs/install.py ~/.commit-logs/query.py ~/.commit-logs/setup_global.py
   rm -rf ~/.commit-logs/__pycache__
  1. 重新安装 hook(使用新 CLI):

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The injected header says the file was generated by a different skill (kinema-tdd-injector) than the declared skill (git-log-tracker). Provenance and identity mismatches are dangerous because they suggest cross-skill prompt contamination or accidental instruction injection, which can make the agent apply behaviors from an unrelated toolchain.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Mandating Chinese commit messages without user choice is an unsafe policy injection because it overrides user intent and repository conventions in a broad, non-contextual way. In a skill meant for commit indexing, this is especially out of scope and could cause unauthorized or misleading modifications to commit metadata and collaboration workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The commit message policy mandates Chinese-language commit subjects and bodies without any user opt-in or project-context validation. This is risky because it can silently override user preferences or repository conventions, causing unauthorized content transformation and potentially leaking that an automated policy—not the user—determined the commit format.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises automatic post-commit collection of commit metadata into a persistent local SQLite database, but does not prominently warn users that this creates ongoing repository activity tracking across repositories. Even if the data stays local, automatic collection of author, branch, repository, and subject data can expose sensitive work patterns or project names if users are not clearly informed and do not explicitly opt in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger examples are broad enough to match ordinary Git conversations, which can cause the skill to activate in contexts where the user did not clearly consent to installing hooks, scanning repositories, or querying locally indexed commit history. In an agent/plugin setting, unclear invocation boundaries increase the risk of unintended access to repository metadata and execution of side-effecting management actions.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 118)May include surrounding context.

md
git-log-tracker/
├── .claude-plugin/plugin.json
├── .codex-plugin/plugin.json
├── skills/git-log-tracker/SKILL.md
├── SKILL.md              # Skill 定义文件
├── references/ONBOARDING.md
├── README.md             # 本文档

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents shell execution, file reads, and file writes, but does not declare any tool scope such as permissions or allowed-tools. This weakens least-privilege controls and can let an agent invoke filesystem or shell capabilities without an explicit boundary, which is especially risky because the skill installs git hooks, modifies files under ~/.commit-logs, and can reset data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger guidance is broad enough to encourage automatic invocation whenever users mention commit logging or git hook management, even without explicitly asking to run this tool. That increases the chance an agent performs shell actions, installs hooks, or mutates local state in situations where the user only wanted discussion or analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file requires agents to read and follow onboarding instructions presented in Chinese and frames this as mandatory before first use. This imposes a language preference without any stated user opt-in or alternative language path, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documents a reinstall command that deletes the data directory and reinitializes state, but it does not prominently warn about irreversible data loss at the point of use. In an agent context, that omission can lead to accidental destruction of the user's commit index, labels, and configuration through routine troubleshooting or cleanup flows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs the agent in Chinese and requires it to use a Chinese prompt for the initial user interaction, but it does not provide any user opt-in or alternative language option. This is a natural-language locale policy issue because it imposes a specific language on the interaction without justification.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/cli.py (reported line 163)May include surrounding context.

python
"""
    try:
        # Get current branch
        result = subprocess.run(
            ["git", "branch", "--show-current"],
            cwd=repo_path,
            capture_output=True, text=True, timeout=2,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/cli.py (reported line 171)May include surrounding context.

python
current = result.stdout.strip() or "(detached)"

        # Get all branches
        result = subprocess.run(
            ["git", "branch", "--list"],
            cwd=repo_path,
            capture_output=True, text=True, timeout=2,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/cli.py (reported line 418)May include surrounding context.

python
def cmd_global(args):
    """Configure global git template for automatic hook installation."""
    if args.off:
        result = subprocess.run(
            ["git", "config", "--global", "--get", "init.templateDir"],
            capture_output=True, text=True,
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/cli.py (reported line 423)May include surrounding context.

python
capture_output=True, text=True,
        )
        if result.stdout.strip() == str(TEMPLATE_DIR):
            subprocess.run(["git", "config", "--global", "--unset", "init.templateDir"])
            print("Unset git global init.templateDir")
        else:
            print("init.templateDir is not set to our template dir, skipping unset")

Static analysis

No suspicious patterns detected.