Back to skill

Security audit

Git Reporter

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local Git report generator, but crafted report parameters could be inserted into Bash commands and run unintended shell code.

Review before installing. This skill does not appear to exfiltrate data or persist itself, but it will inspect local repository metadata and work-in-progress state. Avoid using untrusted or oddly formatted values for --author or day counts until the command templates add strict validation or structured argument passing, and be cautious in repositories with sensitive commit messages, branch names, stash entries, or contributor emails.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:57
Finding

Potential Shell Command Injection Through Unvalidated Report Parameters

Content
View full analysis
/tmp/git-reporter-poc) ``` 3. The agent substitutes the value i ...[truncated 1226 chars]
Remediation
View remediation

other

Note
Location
SKILL.md:43
Finding

Unnecessary Collection of Contributor Email Addresses

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Automatically choosing the output language based on commit message language changes behavior using repository content rather than explicit user preference. While not directly enabling code execution or privilege escalation, it can surprise users, leak linguistic signals from commit history into the response, and reduce predictability for a tool that processes potentially sensitive local development data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language triggers are broad enough that ordinary requests like '帮我写今天的站会' or '生成一下本周的周报' could invoke the skill without an explicit command. Because this skill reads local git history, branch state, stash data, and uncommitted diffs, unintended activation can expose repository-derived content or summarize sensitive work context when the user did not clearly intend to grant that access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description says it uses local git commands but does not clearly warn that it will inspect commit history, branch state, stash entries, author identity, and uncommitted changes. Because the workflow includes git status, git diff, git diff --cached, and contributor enumeration, a user may unknowingly disclose sensitive local development details to the agent output.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-trigger conditions are broad enough to match common requests like writing a daily update or weekly report, which can cause the skill to activate without the user realizing it will inspect local git history, branches, stashes, and uncommitted changes. In this skill’s context, unintended activation exposes sensitive repository metadata and work-in-progress details, so the issue is more dangerous than a generic false trigger.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and description indicate the skill's example output is presented in Chinese only, implying a fixed output language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction '语言跟随项目' requires output to follow the language detected in commit messages, with no user opt-in or override. This imposes a locale/language choice derived from repository content instead of allowing the user to choose their preferred output language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown example presents headings and explanatory text in both Chinese and English, which can implicitly impose a language/locale format on users without opt-in. Under the language/locale policy check, this is a natural-language policy concern because no rationale or user choice is provided for the mixed-language output style.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.