Back to skill

Security audit

Git Commit Helper Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Git commit-message helper that reads staged Git change statistics and does not show hidden credential access, network calls, writes, or persistence.

Review the generated commit message before use, especially because the implementation analyzes only staged file names and change counts rather than full code semantics. If you install from the README, prefer a pinned or trusted ClawHub installer version instead of an unpinned latest command.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · index.js (reported line 33)May include surrounding context.

js
'.json': 'chore',
  '.yml': 'chore',
  '.yaml': 'chore',
  '.env': 'chore'
};

// 主函数:生成 commit message

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to execute npx clawhub@latest install ..., which fetches and runs the latest published package version at execution time. This creates a supply-chain risk: a compromised publisher account, malicious update, or breaking release could cause arbitrary code execution on a user's machine when they follow the installation instructions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This local-install example still uses npx clawhub@latest, so the helper tool itself is downloaded at its newest version and executed before installing the local skill. Even though the target skill path is local, the unpinned bootstrap command exposes users to arbitrary code execution through a compromised or unexpected upstream package release.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example trigger "帮我生成 commit message" is a generic natural-language request rather than a narrowly scoped invocation phrase. The README does not provide explicit trigger boundaries, exclusions, or negative examples, so the skill could be invoked on ordinary chat phrasing that happens to mention commit messages.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase is broad and resembles normal conversational or development workflow language, which increases the chance the skill is invoked unintentionally during ordinary repository work. Because the skill is designed to analyze current git changes, accidental activation could cause unintended access to sensitive code diffs or commit-related context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The top-level description and exported skill description are presented only in Chinese, with no indication that users can choose another language for the skill interface. In combination with the language default, this creates a locale-specific experience without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code sets the default language to 'zh', and the exported execute entrypoint repeats that default, causing the skill to generate Chinese output unless the user explicitly overrides it. That is a natural-language policy concern because it forces a specific language by default rather than offering a neutral default or explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The natural-language description is written only in Chinese ("智能 Git Commit Message 生成器"), which can impose a language choice on users without offering an alternative or documenting a locale-specific purpose. This matches the policy concern for language or locale constraints that are not optional or justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This JavaScript file contains natural-language strings and comments primarily in Chinese, and the demonstrated execution flow starts with Chinese-language messaging and tests Chinese output first. While the helper supports both 'zh' and 'en', the user-facing test script itself does not offer an explicit language choice before using a fixed locale in its messages, which may conflict with a language/locale choice policy.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:73