Back to skill

Security audit

Shadows Smart Commit

Security checks for vulnerabilities and agentic risk

Overview

This is a local git commit helper, but it can stage and commit on broad triggers and its secret check may print secret values, so users should review it carefully before installing.

Install only if you are comfortable with an agent running local git staging and commit commands. Review the proposed files and commit message before any write action, remove or approve any co-author trailer yourself, and avoid running the built-in secret scan where terminal output is logged or shared.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:82
Finding

Mandatory Commit Template Injects Potentially False Third-Party Attribution

Content
View full analysis
``` **Types**: `feat`, `fix`, `refactor`, `docs`, `test`, `chore`, `perf`, `style`, `build`, `ci` **Rules**: - Subject line: max 72 characters, imperative mood ("add" not "added") - Focus on WHY, not WHAT (the diff shows WHAT) - Include scope when changes are localized to a module - Use HEREDOC for multi-line messages to preserve formatting: ```bash git commit -m "$(cat <<'EOF' type(scope): subject line Body explaining the motivation. Co-Authored-By: Claude EOF )" ``` ``` This trailer is presented as part of the standard commit format rather than as an optional attribution requiring user approval. Conventional Commits does not require a co-author trailer. If the named party did not actually contribute to the changes, the instruction causes inaccurate authorship metadata to be written permanently into repository history. Because the behavior is embedded in the Skill instructions, loading and following the Skill changes the expected commit operation by adding unrelated metadata. This is best classified as instruction hijacking rather than code execution or privilege escalation. ### Attack Path 1. A user invokes the Skill to commit repository changes. 2. The agent follows the mandatory commit-message generation instructions. 3. The fixed `Co-Authored-By` trailer is inserted without confirming authorship or obtaining explicit user consent. 4. `git commit` records the trailer permanently in the local repository. 5. If the commit is subsequent ...[truncated 734 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:51
Finding

Secret Scanner Exposes Matched Credentials in Terminal and Agent Output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

md
2. **Specific staging** — NEVER `git add .` — always name files explicitly
3. **Conventional format** — `type(scope): message` always
4. **Meaningful messages** — explain intent, not just what changed
5. **No force push** — NEVER `git push --force` on main/master
6. **No amend** — create NEW commits unless explicitly asked to amend
7. **No skip hooks** — NEVER use `--no-verify`
8. **Atomic commits** — one logical change per commit

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are overly broad because they include generic phrases like "commit," "save my changes," and even "push," plus an automatic post-task trigger. This can cause the skill to invoke in situations where the user did not intend repository-modifying actions, increasing the chance of accidental staging or committing sensitive or incomplete work.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.