T09 · Insecure Skill Coding Practices
- Location
SKILL.md:57- Finding
Unreviewed Whole-Repository Staging and Remote Push
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 57
Vulnerability Type: Unrestricted repository staging and publication
Risk Level: HighEvidence
text 5. Submit: git add -A && git commit && git pushThe source instruction has been translated into English without changing the command.
Technical Analysis
The workflow instructs the agent to execute
git add -A, which stages all tracked modifications, deletions, and untracked files under the repository. It then commits and pushes the staged content to the configured remote repository.There are no documented safeguards requiring:
- Explicit path allowlisting
- Review of the staged diff
- Detection of credentials or other secrets
- Separation of unrelated concurrent changes
- Verification of the destination remote
- User confirmation before committing or pushing
The command does not itself bypass repository authentication or obtain additional operating-system privileges. However, when executed by an agent that already possesses valid repository credentials, it can publish content beyond the files legitimately affected by the governance task.
Attack Path
- A sensitive, unrelated, or attacker-controlled file is created inside the repository.
- The file remains untracked, or an existing tracked file contains unrelated modifications.
- The governance workflow is invoked.
git add -Astages all repository changes, including the unrelated content.git commitrecords those changes without a required staged-diff review.git pushtransmits the resulting commit to the configured remote.- Users with access to the remote repository can retrieve the unintentionally published content.
Impact Assessment
Successful exploitation can disclose any file located within the repository that the executing agent can read and stage. It can also publish unrelated modifications or deletions made by other processes or users.
The affected scope is limited ...[truncated 386 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
git add -Awith explicit staging of an allowlisted set of files produced by the current audit. - Capture the exact moved-file list and stage only those paths, using path separators and safe quoting.
- Run
git diff --cached --name-statusandgit diff --cachedbefore committing. - Abort if the staged set contains files outside the approved archive and audit-report directories.
- Run secret scanning against all staged content.
- Verify the repository root and configured remote before any write or network operation.
- Require explicit user approval before
git commitand especially beforegit push. - Avoid combining staging, committing, and pushing into a single unconditional command chain.
- Perform the push with a narrowly scoped repository identity that cannot modify unrelated repositories or protected branches.
- Replace
