Back to skill

Security audit

Code Sync

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed bulk Git sync helper, but it can automatically push or pull across many repositories and may expose credential-bearing remote URLs in its scan output.

Install only if you are comfortable with a skill that can act across many repositories. Before use, verify the configured base directory, review which repositories will be touched, avoid Git remote URLs containing credentials, and prefer adding an explicit confirmation step before any bulk push or pull.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/scan.sh:84
Finding

Credential Disclosure Through Unredacted Git Remote URLs

Content
View full analysis
/dev/null || echo "") remote_url="" [[ -n "$remote" ]] && remote_url=$(git -C "$dir" config "remote.${remote}.url" 2>/dev/null || echo "") # Dirty count: modified + untracked files dirty_count=$(git -C "$dir" status --porcelain 2>/dev/null | wc -l | tr -d ' ') # Upstream tracking: ahead/behind counts has_upstream=false ahead=0 behind=0 if git -C "$dir" rev-parse --abbrev-ref "@{u}" >/dev/null 2>&1; then has_upstream=true counts=$(git -C "$dir" rev-list --count --left-right "HEAD...@{u}" 2>/dev/null || echo "0 0") ahead=$(echo "$counts" | awk '{print $1}') behind=$(echo "$counts" | awk '{print $2}') fi # Comma separator between objects $first && first=false || echo "," # Build JSON object path_clean="${dir%/}" name=$(basename "$dir") printf ' {"path":"%s","name":"%s","branch":"%s","remote":"%s","remote_url":"%s","dirty_count":%d,"has_upstream":%s,"ahead":%d,"behind":%d' \ "$(json_escape "$path_clean")" \ "$(json_escape "$name")" \ "$(json_escape "$branch")" \ "$(json_escape "$remote")" \ "$(json_escape "$remote_url")" \ ``` ### Technical Analysis The script reads the complete URL associated with the current branch's Git remote and emits it into the JSON report. Git supports remote URLs containing user information, passwords, personal access tokens, or other embedded credentials, for example: ```text https://username:token@example.com/organization/repository.git ``` No credential detection or redaction occurs before `remote_url` is passed to `printf`. The synchronization logic only needs remote identity and repository status; exposing authentication material is not required for the declared workflow. Because the report is intended fo ...[truncated 1231 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/scan.sh:31
Finding

Malformed JSON and Output Injection Through Incomplete String Escaping

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose says this skill should batch-sync repositories across machines, specifically for end-of-day pushing and morning pulling across ~/code. However, the supplied script only enumerates git repos in the target directory structure and reports status as JSON. Its only network-affecting operation is an optional git fetch, which updates remote-tracking metadata but does not pull working trees or push local changes. The primary purpose of the code is repository discovery and status inspection, not synchronization. Access to repository metadata and remote URLs is consistent with git tooling, but the advertised sync behavior is not implemented in this chunk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

The workflow delegates autonomous decision-making for mutating actions by performing batch operations 'auto, no confirmation' after categorization. In a skill that can traverse many repositories and interact with remotes, lack of confirmation removes an important human checkpoint and raises the risk of mass unintended state changes or data exposure.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
## Workflow (shared by both modes)

1. **Scan** → 2. **Categorize** → 3. **Batch action** (auto, no confirmation) → 4. **Handle exceptions** (interactive) → 5. **Summary**

If all repos are up-to-date, report that and stop.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill authorizes automatic batch git push and git pull --ff-only across all discovered repositories with 'auto, no confirmation'. In the context of a bulk repo-management skill operating over ~/code, this can cause unintended remote publication of local commits, unexpected workspace changes, or synchronization against the wrong set of repositories if scanning/configuration is inaccurate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill description embeds specific Chinese trigger phrases such as '下班同步', '上班更新', and '同步代码' as activation and mode-selection inputs, but does not explicitly state that language selection is optional or user-configurable. This can be interpreted as a locale/language policy issue because the skill defines language-specific behavior without an opt-in statement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.