T05 · Unauthorized Access and Privilege Escalation
- Location
deploy-public.sh:102- Finding
Unbounded Private-to-Public File Disclosure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a real private-to-public publishing tool, but it also performs under-disclosed high-impact actions such as broad branch deletion, automatic npm publishing, and local secret use.
Install only if you are prepared for it to mutate a public GitHub repository, merge changes, create releases, possibly create the repo, delete remote branches, and publish npm packages. Review and modify the script first: add a dry run, restrict branch cleanup to branches it created, use an allowlist or secret scan before public commits, remove --no-verify, and require explicit opt-in before reading 1Password credentials or running npm publish.
deploy-public.sh:102Unbounded Private-to-Public File Disclosure
deploy-public.sh:181Destructive Deletion of Unrelated Remote Branches
deploy-public.sh:247Plaintext npm Credential Can Remain in an Untrapped Temporary Directory
deploy-public.sh:242Undocumented Automatic Publication of Packages to npm
The skill metadata and documentation claim a narrow private-to-public sync that excludes only ai/, but the referenced behavior includes materially broader and more sensitive actions: creating repositories, deleting branches, publishing to npm, and retrieving secrets. This mismatch is dangerous because a user or calling agent may grant repo and secret access under false assumptions, leading to unintended destructive changes or public release of code/packages.
Referenced artifact was not completely inspected
3. THEN run `deploy-public.sh` (pulls notes from private release)
Using git commit --no-verify bypasses client-side hooks such as secret scanning, policy checks, or content validation that may be relied upon to prevent unsafe publication. In a script that sanitizes and republishes code to a public repo, skipping those controls increases the risk that prohibited or sensitive content is committed and pushed unnoticed.
BRANCH="$HARNESS_ID/deploy-$(date +%Y%m%d-%H%M%S)"
git add -A
git commit --no-verify -m "$COMMIT_MSG (from $COMMIT_HASH)"
if [[ "$EMPTY_REPO" == "true" ]]; then
# Empty repo: push directly to main (no base branch to PR against)
The stated skill purpose is repo synchronization and release mirroring, but the script also performs npm publication using retrieved credentials. That is a materially broader and more sensitive side effect than the declared behavior, creating a supply-chain risk where running a repo-sync tool can unexpectedly publish packages to a public registry.
The script writes the npm auth token into a plaintext .npmrc file in the working tree before publishing. Even if later removed, the token can be exposed through process interruption, debugging, file-system monitoring, backup tools, permissive file permissions, or accidental inclusion in subsequent operations.
# Publish root package (if not private)
if [[ "$IS_PRIVATE" != "true" ]]; then
echo "//registry.npmjs.org/:_authToken=${NPM_TOKEN}" > .npmrc
ROOT_PUBLISH_ERR=$(npm publish --access public 2>&1)
if [[ $? -eq 0 ]]; then
echo " ✓ Published root package to npm"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
else
classify_npm_publish_error "root" "$ROOT_PUBLISH_ERR"
fi
rm -f .npmrc
else
echo " - Root package is private. Skipping root npm publish."
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
else
classify_npm_publish_error "root" "$ROOT_PUBLISH_ERR"
fi
rm -f .npmrc
else
echo " - Root package is private. Skipping root npm publish."
fi
This repeats the same risky pattern for each tool package by writing the npm auth token into a plaintext per-tool .npmrc file. Multiple writes increase the exposure surface and the chance of leakage during failures, concurrent tooling, or accidental file capture.
TOOL_PRIVATE=$(node -p "require('./${TOOL_DIR}package.json').private || false" 2>/dev/null)
if [[ "$TOOL_PRIVATE" != "true" ]]; then
TOOL_NAME=$(node -p "require('./${TOOL_DIR}package.json').name" 2>/dev/null)
echo "//registry.npmjs.org/:_authToken=${NPM_TOKEN}" > "${TOOL_DIR}.npmrc"
TOOL_PUBLISH_ERR=$(cd "$TOOL_DIR" && npm publish --access public 2>&1)
if [[ $? -eq 0 ]]; then
echo " ✓ Published $TOOL_NAME to npm"
The README advertises automatic PR merge and deploy-branch cleanup but does not warn users that these actions are irreversible or may modify/delete remote state. In a repo-publication workflow, this can lead to unintended public disclosure, accidental release propagation, or loss of recovery points if a user runs the tool with the wrong repository or without reviewing the generated changes.
The skill describes cloning, copying, PR creation, merging, and release syncing, but does not clearly warn that it may perform destructive repository operations or irreversible publication actions. In this context, the omission increases the chance that an operator or autonomous agent runs it against the wrong repository or with excessive permissions, causing unintended exposure or repository state changes.
The script reads a local 1Password service-account token and uses it to fetch an npm credential, even though the advertised function is repository sync. Accessing secret-management material expands the trust boundary and enables unintended package publication if the script is invoked in an environment where those secrets are available.
Sensitive credential access occurs silently at the point of operation, with no upfront disclosure or confirmation near the secret read. In agent or automation contexts, this increases the chance that a user runs the script without realizing it will touch local secret material and initiate external publication actions.
No suspicious patterns detected.