Back to skill

Security audit

GitX

Security checks for vulnerabilities and agentic risk

Overview

GitX is a clearly disclosed Git workflow helper whose repository and GitHub actions match its stated purpose.

Install this only if you want an agent to help operate Git and GitHub in your repositories. Review commands before using workflows that commit, push, create PRs or issues, or resolve conflicts, and treat secret-scan results as sensitive even though the skill instructs redaction.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
Use this portable `SKILL.md` with coding agents that support the Agent Skills format.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

md
For `gitx scan`:

1. Perform a read-only scan of non-ignored working-tree files, staged content, commits reachable from `HEAD`, and locally available `origin/*` history. Do not fetch automatically; state that pushed-history results reflect the locally available remote-tracking refs.
2. Prefer an installed secret scanner such as Gitleaks or TruffleHog without installing tools or uploading repository content. When none is available, inspect filenames and content for likely API keys, access tokens, passwords, connection strings, private keys, credentials, tracked `.env` files, and other sensitive configuration. Distinguish real credentials from obvious placeholders and examples.
3. Classify each finding as `UNCOMMITTED`, `STAGED`, `COMMITTED LOCALLY`, or `PUSHED TO ORIGIN`. Use `PUSHED TO ORIGIN` only when the containing commit is reachable from a locally available `origin/*` ref.
4. Report the severity, exposure class, credential type, file path, line or commit when available, and a recommended action. Redact every value; never print a complete credential or secret.
5. For a pushed credential, say to revoke or rotate it immediately and explain that deleting the file or making another commit does not invalidate the credential. Discuss history rewriting only when the user explicitly asks for remediation.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default prompt uses a broad, natural-language invocation phrase ('Use $gitx to commit my changes intelligently and safely') that could match ordinary user requests about committing changes. This can cause the skill to activate in situations the user did not explicitly intend, giving a Git-capable skill access to repository operations and related workflows more often than necessary.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.