other
- Location
SKILL.md:153- Finding
Unnecessary Full-Content Access to Private Keys and Credential Files
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This secret-audit skill is related to its stated purpose, but it needs review because it can read full credential files and may falsely skip scans for local or private repositories.
Before installing, be aware that this skill may inspect highly sensitive files in the current workspace. Use it only in repositories where agent access to potential secrets is acceptable, do not rely on its no-risk answer for local/private repositories, and prefer requiring confirmation or metadata-only handling before opening private keys or production credential files.
SKILL.md:153Unnecessary Full-Content Access to Private Keys and Credential Files
SKILL.md:33Repository Visibility Gate Can Produce False “No Risk” Conclusions
The prescribed exit message is written in Chinese and is presented as the required response, with similar Chinese-only mandated text later in the file. This imposes a specific language on users without asking for preference or documenting a justified locale restriction.
This mandated user-facing message is written only in Chinese and gives no option to adapt to the user's preferred language. That violates the language/locale policy criterion because it constrains output language without opt-in or clear regional justification.
The required private-repo exit response is specified only in Chinese, implying the skill must answer in that language regardless of user preference. There is no documented justification that this skill is region-specific or limited to Chinese-speaking users.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| Docker | `.env`, `.env.*` |
| Terraform | `*.tfstate`, `*.tfstate.*`, `.terraform/`, `terraform.tfvars` |
| Firebase | `google-services.json`, `GoogleService-Info.plist`, `.env` |
| Any | `*.pem`, `*.key`, `*.p12`, `*.pfx`, `credentials.json`, `*.log` |
3. Note any missing patterns as findings.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| Docker | `.env`, `.env.*` |
| Terraform | `*.tfstate`, `*.tfstate.*`, `.terraform/`, `terraform.tfvars` |
| Firebase | `google-services.json`, `GoogleService-Info.plist`, `.env` |
| Any | `*.pem`, `*.key`, `*.p12`, `*.pfx`, `credentials.json`, `*.log` |
3. Note any missing patterns as findings.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| Docker | `.env`, `.env.*` |
| Terraform | `*.tfstate`, `*.tfstate.*`, `.terraform/`, `terraform.tfvars` |
| Firebase | `google-services.json`, `GoogleService-Info.plist`, `.env` |
| Any | `*.pem`, `*.key`, `*.p12`, `*.pfx`, `credentials.json`, `*.log` |
3. Note any missing patterns as findings.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Use Glob to find files that commonly hold secrets:
**/.env
**/.env.*
**/.npmrc
**/credentials.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**/.env
**/.env.*
**/.npmrc
**/credentials.json
**/credentials.*.json
**/service-account.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**/service-account-*.json
**/google-services.json
**/GoogleService-Info.plist
**/secrets.yaml
**/secrets.yml
**/secret*
**/terraform.tfvars
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**/google-services.json
**/GoogleService-Info.plist
**/secrets.yaml
**/secrets.yml
**/secret*
**/terraform.tfvars
**/*.tfstate
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**/google-services.json
**/GoogleService-Info.plist
**/secrets.yaml
**/secrets.yml
**/secret*
**/terraform.tfvars
**/*.tfstate
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**/config/database.yml **/config/secrets.yml **/config/master.key **/.aws/credentials **/aws-credentials.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| Severity | File | Line | What was found |
|----------|------|------|----------------|
| 🔴 Critical | `config.js` | 12 | GitHub personal access token |
| 🟡 High | `.env` | 3 | OpenAI API key |
| 🟢 Medium | `app.config` | 5 | Database password |
The Purpose section says the skill uses AI directly to read and analyze files with 'no scripts, no regex database to maintain.' However, the workflow explicitly instructs running git status, git remote -v, gh repo view, git ls-files, glob-based scans, and optional grep queries. That is an active contradiction between the documentation’s implementation claim and the described operational steps.
The phrase "Any concern about pushing code to GitHub or open-sourcing" is broad and not bounded by specific examples or exclusions. It could overlap with many normal repository-management requests that are not specifically asking for a security-leak audit, increasing the chance of unintended invocation.
This caveat is another required user-facing string in Chinese only. Requiring a fixed locale in operational messages without opt-in is a natural-language policy issue under the language/locale rule.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
| Rust | `.env`, `.env.*`, `target/` |
| Docker | `.env`, `.env.*` |
| Terraform | `*.tfstate`, `*.tfstate.*`, `.terraform/`, `terraform.tfvars` |
| Firebase | `google-services.json`, `GoogleService-Info.plist`, `.env` |
| Any | `*.pem`, `*.key`, `*.p12`, `*.pfx`, `credentials.json`, `*.log` |
3. Note any missing patterns as findings.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
| Rust | `.env`, `.env.*`, `target/` |
| Docker | `.env`, `.env.*` |
| Terraform | `*.tfstate`, `*.tfstate.*`, `.terraform/`, `terraform.tfvars` |
| Firebase | `google-services.json`, `GoogleService-Info.plist`, `.env` |
| Any | `*.pem`, `*.key`, `*.p12`, `*.pfx`, `credentials.json`, `*.log` |
3. Note any missing patterns as findings.
The skill is advertised as an audit/scanning capability, but Phase 5 instructs the agent to create or modify .gitignore. That expands the skill from analysis into repository mutation, increasing the chance of unintended file changes and enabling actions beyond the stated scope if invoked automatically.
The manifest says the skill scans the working tree for exposed credentials and misconfigured .gitignore files. Phase 0 adds repository/remote visibility inspection via git remote -v and gh repo view, which goes beyond a pure working-tree scan into remote repository metadata checks. While related to exposure assessment, this behavior is not clearly reflected in the manifest description.
No suspicious patterns detected.