Back to skill

Security audit

GitHub Trending

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches public GitHub Trending pages and formats reports, with no evidence of persistence, credential access, or hidden system changes.

Install only if you are comfortable with a skill that runs a local Python script to fetch public GitHub Trending pages. Treat repository names and descriptions in its output as untrusted public content, especially if exporting Markdown or asking an agent to analyze the results.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_trending.py:142
Finding

Untrusted GitHub Repository Descriptions Enter the Agent and Markdown Pipelines Without Sanitization

Content
View full analysis
dict[str, Any]: full_name = repo.get("repo") author = None name = None if isinstance(full_name, str) and "/" in full_name: author, name = full_name.split("/", 1) description = repo.get("description") language = repo.get("language") title = title_from_description(description) english_description = description if is_english_text(description) else None repo["full_name"] = full_name repo["author"] = author repo["name"] = name repo["author_avatar"] = f"https://github.com/{author}.png" if author else None repo["title"] = title repo["title_en"] = title if is_english_text(title) else None repo["summary"] = truncate(description) repo["summary_en"] = truncate(english_description) repo["primary_lang"] = language repo["lang_color"] = LANGUAGE_COLORS.get(language) if updated_at is not None: repo["updated_at"] = updated_at return repo ``` The description is also inserted into Markdown with only pipe and newline escaping: ```python def escape_markdown_cell(value: Any) -> str: if value is None: return "-" return str(value).replace("|", "\\|").replace("\n", " ") ``` ```python for repo in report["repositories"]: lines.append( "| {rank} | {repo} | { ...[truncated 3790 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to run a Python script that fetches live GitHub Trending data, which implies network-capable execution, but it does not declare any tool scope or allowed-tools restrictions. This creates an authorization gap where runtime behavior may exceed intended permissions, making it harder to constrain, audit, or sandbox outbound access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code defines is_english_text using an ASCII-letter threshold and then uses it to suppress non-English descriptions and titles from the *_en fields. This embeds a language preference in the skill's behavior without user opt-in or a documented locale justification, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.