Back to skill

Security audit

沙箱环境下的 git 安全操作与仓库恢复

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a Git recovery guide, but it tells agents to find and use stored GitHub credentials without asking the user.

Review carefully before installing. Do not allow this skill to inspect or reuse stored GitHub tokens, environment secrets, or SSH keys unless you explicitly intend that for the exact repository operation. Prefer an interactive GitHub login or a scoped credential flow, and require approval before persistent PATH, git config, remote URL, or push changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Ssd 3

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

This is a detailed playbook for locating, reading, validating, and operationalizing GitHub tokens from ~/.git-credentials, environment variables, git helper configuration, and GitHub CLI files. In context, the skill is nominally about safe git operations, so embedding a credential-harvesting workflow is more dangerous because it is unrelated to the core purpose and can be reused to impersonate the user or access remote resources under their account.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

Referencing ~/.git-credentials here is part of a broader instruction set to mine local stored secrets for authentication. The context makes it more dangerous because the skill frames secret access as a routine recovery step instead of a privileged action requiring consent.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
| `git push` 报 `! [rejected] ... (fetch first)` | 远端确实有新提交(例如 GitHub Actions 的每日采集提交)。**不要**用 `git pull --rebase`,走 §4 |
| `git rebase <sha>` 报 `error: could not mark as interactive: No such file or directory` | 沙箱下 rebase 要建 `.git/rebase-*` 目录,创建失败;**紧接着 `.git` 会被整个删掉**(实测,见 §2) |
| `git log` 突然报 `fatal: not a git repository` | 上一条的后果,进入 §5 恢复流程 |
| `git push` 报 `could not read Username ... terminal prompts disabled` | 全局 `credential.https://github.com.helper=!gh auth git-credential` 生效,但 `gh auth status` 是「未登录」。**先按 §8 找现成 token**(通常 `~/.git-credentials` 里就有);找不到再回落 `git config credential.https://github.com.helper store` |
| `gh auth status` 说未登录,但 `~/.git-credentials` 里存着一行 `https://<user>:gho_xxx@github.com` | **直接用这行里的 token**,别去麻烦用户。见 §8 |
| `git branch --set-upstream-to=origin/master` 报 `the requested upstream branch does not exist`,但 `FETCH_HEAD` 里明明有那个 sha | `refs/remotes/**` 写入被沙箱吃掉(同 §3)。**注意**:此时 `.git/refs/remotes/` 目录可能压根没被创建,`ls` 报 ENOENT。按 §3 直写即可;`FETCH_HEAD` 的 sha == 本地 HEAD 就能判定 push 已成功 |
| `git -c http.proxy= -c https.proxy= fetch origin main` 成功,但同参数 `push` 报 `Recv failure: Connection was reset` | 下载走直连可以、**上传必须走代理**。见 §7 换 `socks5://` |

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The symptom table directly advises using an existing token from ~/.git-credentials and tells the operator not to involve the user. That is a clear credential-access pattern that can lead to unauthorized use of stored secrets and reduces opportunities for user awareness or approval.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

This line explicitly tells the operator to use the token found in ~/.git-credentials directly and avoid bothering the user. That is a strong indicator of unauthorized credential use and materially increases the chance of misuse of stored secrets.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
| `git rebase <sha>` 报 `error: could not mark as interactive: No such file or directory` | 沙箱下 rebase 要建 `.git/rebase-*` 目录,创建失败;**紧接着 `.git` 会被整个删掉**(实测,见 §2) |
| `git log` 突然报 `fatal: not a git repository` | 上一条的后果,进入 §5 恢复流程 |
| `git push` 报 `could not read Username ... terminal prompts disabled` | 全局 `credential.https://github.com.helper=!gh auth git-credential` 生效,但 `gh auth status` 是「未登录」。**先按 §8 找现成 token**(通常 `~/.git-credentials` 里就有);找不到再回落 `git config credential.https://github.com.helper store` |
| `gh auth status` 说未登录,但 `~/.git-credentials` 里存着一行 `https://<user>:gho_xxx@github.com` | **直接用这行里的 token**,别去麻烦用户。见 §8 |
| `git branch --set-upstream-to=origin/master` 报 `the requested upstream branch does not exist`,但 `FETCH_HEAD` 里明明有那个 sha | `refs/remotes/**` 写入被沙箱吃掉(同 §3)。**注意**:此时 `.git/refs/remotes/` 目录可能压根没被创建,`ls` 报 ENOENT。按 §3 直写即可;`FETCH_HEAD` 的 sha == 本地 HEAD 就能判定 push 已成功 |
| `git -c http.proxy= -c https.proxy= fetch origin main` 成功,但同参数 `push` 报 `Recv failure: Connection was reset` | 下载走直连可以、**上传必须走代理**。见 §7 换 `socks5://` |
| 同参数 `push` **不报错也不结束**(挂住,4 分钟无任何输出,直到被杀) | 与上一条同源:上传方向直连走不通,且这次是**静默挂起**而不是 `Recv failure`。见 §7 —— 别等,直接换 `socks5://` |

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section explicitly instructs the agent to search local credential stores and environment variables for existing GitHub tokens and then use them for authentication. Accessing secrets from ~/.git-credentials, environment variables, and CLI config without an explicit per-use consent flow is dangerous because it normalizes credential harvesting and can enable unauthorized repository access or misuse of the user's identity.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

These instructions tell the agent to read and extract tokens from local credential stores and use them without a strong user-facing warning or explicit consent checkpoint. That is dangerous because it encourages secret access as a default troubleshooting step and bypasses normal expectations around credential handling.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

The command cat ~/.git-credentials directly reads a plaintext credential store to reveal an access token. This is straightforward credential access and is especially risky because the skill's declared purpose is git recovery, not secret management.

Content

Scanner excerpt · SKILL.md (reported line 391)May include surrounding context.

用户说「你自己找凭证」时,按下面顺序找,不要打断用户索要 token:

bash
# 1) 最优先:~/.git-credentials(明文存着,通常直接可用)
cat ~/.git-credentials
#   形如 https://oracis:gho_xxxxx@github.com  —— 冒号后就是 token

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The surrounding guidance explains how to parse and use the token from ~/.git-credentials, turning credential access into an operational procedure. This increases the likelihood of secret exposure and unauthorized remote actions under the user's account.

Content

Scanner excerpt · SKILL.md (reported line 392)May include surrounding context.

bash
# 1) 最优先:~/.git-credentials(明文存着,通常直接可用)
cat ~/.git-credentials
#   形如 https://oracis:gho_xxxxx@github.com  —— 冒号后就是 token

# 2) 环境变量

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The command parses a password/token directly out of ~/.git-credentials and uses it for subsequent API calls. This is explicit secret extraction from local storage and creates a direct path from stored credentials to network use, increasing the chance of unauthorized access or accidental leakage in logs, process lists, or history.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

This command extracts the password component from a URL stored in ~/.git-credentials, which is direct programmatic secret harvesting. In context, it feeds immediately into external API use, making the credential exposure chain concrete and actionable.

Content

Scanner excerpt · SKILL.md (reported line 453)May include surrounding context.

先用 API 确认 scope(比猜准,且不用翻设置页):

bash
TOKEN=$(python -c "import os;from urllib.parse import urlparse;print(urlparse(open(os.path.expanduser('~/.git-credentials'),encoding='utf-8').read().strip().split(chr(10))[0]).password)")
curl -sS -o /dev/null -D - -H "Authorization: token $TOKEN" https://api.github.com/user \
  | grep -i x-oauth-scopes
# 期望里要有 workflow;只有 gist, read:org, repo 就是缺

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill instructs the operator to inspect ~/.ssh/config and rely on an existing private key identity for GitHub SSH authentication. While not extracting the key material directly, it operationalizes existing authentication assets and encourages use of local credentials without an explicit approval boundary, which can enable unauthorized pushes under the user's identity.

Content

Scanner excerpt · SKILL.md (reported line 471)May include surrounding context.

text

2026-09-20 本机实测:SSH **直连即可**(github.com:22 没被墙),且比 https+socks5 还快。
`~/.ssh/config` 里已有 `IdentityFile /c/Users/<user>/.ssh/id_ed25519_gh`,无需额外配置。

**推完要手动修跟踪引用** —— 用 SSH URL 推不会更新 `origin` 的 https 跟踪引用,
于是 `git status -sb` 会显示假的 `ahead N`(按 §3 直写即可):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description is entirely in Chinese and presents the skill's invocation/use conditions only in that language. The policy scope here is natural-language locale choice: the file does not indicate that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill recommends persistent PATH modification at user or machine scope via registry/environment configuration and application restart. Even if framed as a reliability fix, changing global PATH is a broad system-configuration action that can affect unrelated programs, create precedence issues, and persist beyond the immediate git task.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This finding is the same external API interaction to api.github.com with a bearer-like token in the request header. In isolation the destination is legitimate, but in context it compounds the credential-access issue by immediately exfiltrating a locally recovered secret off-host.

Content

Scanner excerpt · SKILL.md (reported line 454)May include surrounding context.

bash
TOKEN=$(python -c "import os;from urllib.parse import urlparse;print(urlparse(open(os.path.expanduser('~/.git-credentials'),encoding='utf-8').read().strip().split(chr(10))[0]).password)")
curl -sS -o /dev/null -D - -H "Authorization: token $TOKEN" https://api.github.com/user \
  | grep -i x-oauth-scopes
# 期望里要有 workflow;只有 gist, read:org, repo 就是缺

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This finding is the same external API interaction to api.github.com with a bearer-like token in the request header. In isolation the destination is legitimate, but in context it compounds the credential-access issue by immediately exfiltrating a locally recovered secret off-host.

Content

Scanner excerpt · SKILL.md (reported line 454)May include surrounding context.

bash
TOKEN=$(python -c "import os;from urllib.parse import urlparse;print(urlparse(open(os.path.expanduser('~/.git-credentials'),encoding='utf-8').read().strip().split(chr(10))[0]).password)")
curl -sS -o /dev/null -D - -H "Authorization: token $TOKEN" https://api.github.com/user \
  | grep -i x-oauth-scopes
# 期望里要有 workflow;只有 gist, read:org, repo 就是缺

Static analysis

No suspicious patterns detected.