Back to skill

Security audit

Code Security Check - 代码仓库安全审计

Security checks for vulnerabilities and agentic risk

Overview

This secret-audit skill is related to its stated purpose, but it needs review because it can read full credential files and may falsely skip scans for local or private repositories.

Before installing, be aware that this skill may inspect highly sensitive files in the current workspace. Use it only in repositories where agent access to potential secrets is acceptable, do not rely on its no-risk answer for local/private repositories, and prefer requiring confirmation or metadata-only handling before opening private keys or production credential files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Warning
Location
SKILL.md:153
Finding

Unnecessary Full-Content Access to Private Keys and Credential Files

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:33
Finding

Repository Visibility Gate Can Produce False “No Risk” Conclusions

Content
View full analysis
🟢 **这是一个本地项目,未使用 Git 管理。本地文件不存在公开泄露风险,无需担心。** → **EXIT. Do not proceed to further phases.** Do not ask to fix anything. **Step 2 — Check for remote (for git repos only):** Run `git remote -v`. If no remote is configured: > 🟢 **这是一个本地 Git 仓库,尚未关联远程仓库(没有 remote),代码不会被推送到任何公开位置,不存在泄露风险。** > 💡 友情提醒:如果未来要推送到公开仓库,建议提前配置 `.gitignore` 防止构建产物和依赖被提交。 → **EXIT. Do not proceed to further phases.** Do not ask to fix anything — a quick reminder is enough. **Step 3 — Check remote visibility (for repos with a remote):** If the remote appears to be on GitHub, try to check its visibility: ```bash gh repo view --json visibility 2>/dev/null || echo "CANNOT_DETERMINE" ``` - If `visibility` is `PRIVATE`: > 🟢 **远程仓库是私有仓库(private),非公开项目不存在泄露风险。** > 💡 友情提醒:确保 `.gitignore` 配置正确,以防将来改为公开仓库时出现意外。 → **EXIT. Do not proceed to further phases.** A friendly reminder is sufficient. ``` ### Technical Analysis The Skill treats the absence of Git metadata, the absence of a configured remote, or private GitHub visibility as proof that no leakage risk exists. It then mandates termination before scanning the working tree. Repository visibility is an exposure factor, not evidence that credentials are absent. A local project may be preparing for its first commit or push. A remote-less repository may later receive a public remote. A private repository may expose secrets to collabo ...[truncated 1698 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prescribed exit message is written in Chinese and is presented as the required response, with similar Chinese-only mandated text later in the file. This imposes a specific language on users without asking for preference or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This mandated user-facing message is written only in Chinese and gives no option to adapt to the user's preferred language. That violates the language/locale policy criterion because it constrains output language without opt-in or clear regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The required private-repo exit response is specified only in Chinese, implying the skill must answer in that language regardless of user preference. There is no documented justification that this skill is region-specific or limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
| Docker | `.env`, `.env.*` |
   | Terraform | `*.tfstate`, `*.tfstate.*`, `.terraform/`, `terraform.tfvars` |
   | Firebase | `google-services.json`, `GoogleService-Info.plist`, `.env` |
   | Any | `*.pem`, `*.key`, `*.p12`, `*.pfx`, `credentials.json`, `*.log` |

3. Note any missing patterns as findings.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
| Docker | `.env`, `.env.*` |
   | Terraform | `*.tfstate`, `*.tfstate.*`, `.terraform/`, `terraform.tfvars` |
   | Firebase | `google-services.json`, `GoogleService-Info.plist`, `.env` |
   | Any | `*.pem`, `*.key`, `*.p12`, `*.pfx`, `credentials.json`, `*.log` |

3. Note any missing patterns as findings.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
| Docker | `.env`, `.env.*` |
   | Terraform | `*.tfstate`, `*.tfstate.*`, `.terraform/`, `terraform.tfvars` |
   | Firebase | `google-services.json`, `GoogleService-Info.plist`, `.env` |
   | Any | `*.pem`, `*.key`, `*.p12`, `*.pfx`, `credentials.json`, `*.log` |

3. Note any missing patterns as findings.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

Use Glob to find files that commonly hold secrets:

text
**/.env
**/.env.*
**/.npmrc
**/credentials.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

text
**/.env
**/.env.*
**/.npmrc
**/credentials.json
**/credentials.*.json
**/service-account.json

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
**/service-account-*.json
**/google-services.json
**/GoogleService-Info.plist
**/secrets.yaml
**/secrets.yml
**/secret*
**/terraform.tfvars

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
**/google-services.json
**/GoogleService-Info.plist
**/secrets.yaml
**/secrets.yml
**/secret*
**/terraform.tfvars
**/*.tfstate

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
**/google-services.json
**/GoogleService-Info.plist
**/secrets.yaml
**/secrets.yml
**/secret*
**/terraform.tfvars
**/*.tfstate

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

**/config/database.yml **/config/secrets.yml **/config/master.key **/.aws/credentials **/aws-credentials.json

text

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

md
| Severity | File | Line | What was found |
   |----------|------|------|----------------|
   | 🔴 Critical | `config.js` | 12 | GitHub personal access token |
   | 🟡 High | `.env` | 3 | OpenAI API key |
   | 🟢 Medium | `app.config` | 5 | Database password |

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Purpose section says the skill uses AI directly to read and analyze files with 'no scripts, no regex database to maintain.' However, the workflow explicitly instructs running git status, git remote -v, gh repo view, git ls-files, glob-based scans, and optional grep queries. That is an active contradiction between the documentation’s implementation claim and the described operational steps.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The phrase "Any concern about pushing code to GitHub or open-sourcing" is broad and not bounded by specific examples or exclusions. It could overlap with many normal repository-management requests that are not specifically asking for a security-leak audit, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This caveat is another required user-facing string in Chinese only. Requiring a fixed locale in operational messages without opt-in is a natural-language policy issue under the language/locale rule.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
| Rust | `.env`, `.env.*`, `target/` |
   | Docker | `.env`, `.env.*` |
   | Terraform | `*.tfstate`, `*.tfstate.*`, `.terraform/`, `terraform.tfvars` |
   | Firebase | `google-services.json`, `GoogleService-Info.plist`, `.env` |
   | Any | `*.pem`, `*.key`, `*.p12`, `*.pfx`, `credentials.json`, `*.log` |

3. Note any missing patterns as findings.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

md
| Rust | `.env`, `.env.*`, `target/` |
   | Docker | `.env`, `.env.*` |
   | Terraform | `*.tfstate`, `*.tfstate.*`, `.terraform/`, `terraform.tfvars` |
   | Firebase | `google-services.json`, `GoogleService-Info.plist`, `.env` |
   | Any | `*.pem`, `*.key`, `*.p12`, `*.pfx`, `credentials.json`, `*.log` |

3. Note any missing patterns as findings.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is advertised as an audit/scanning capability, but Phase 5 instructs the agent to create or modify .gitignore. That expands the skill from analysis into repository mutation, increasing the chance of unintended file changes and enabling actions beyond the stated scope if invoked automatically.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest says the skill scans the working tree for exposed credentials and misconfigured .gitignore files. Phase 0 adds repository/remote visibility inspection via git remote -v and gh repo view, which goes beyond a pure working-tree scan into remote repository metadata checks. While related to exposure assessment, this behavior is not clearly reflected in the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.