Back to skill

Security audit

Wip Release

Security checks for vulnerabilities and agentic risk

Overview

This is a real release automation skill, but it can publish packages and releases, run repository deployment scripts, and perform cleanup actions with guardrails that are too broad for automatic agent use.

Install only if you intend to give this skill release authority over trusted repositories and authenticated publishing accounts. Run it from clean, backed-up working trees, review configured deploy scripts and website paths first, prefer dry-run only on trusted repos, and avoid using broad npm/GitHub credentials until the rollback, script-execution, and confirmation gaps are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (7)

T09 · Insecure Skill Coding Practices

Error
Location
core.mjs:2505
Finding

Shell Command Injection Through Git Branch or Worktree Names

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
core.mjs:2037
Finding

Dry-Run Mode Executes Repository-Controlled Scripts

Content
View full analysis
0) { let allPassed = true; for (const { tool, path } of testFiles) { try { execFileSync('bash', [path], { cwd: dirname(path), stdio: 'pipe', timeout: 30000 }); console.log(` ✓ Tests passed: ${tool}`); } catch (e) { allPassed = false; console.log(` ✗ Tests FAILED: ${tool}`); const output = (e.stdout || '').toString().trim(); if (output) { for (const line of output.split('\n').slice(-5)) console.log(` ${line}`); } } } if (!allPassed) { console.log(''); console.log(' Fix failing tests before releasing.'); console.log(''); return { currentVersion, newVersion, dryRun: false, failed: true }; } } } if (dryRun) { ``` ### Technical Analysis Repository-local `test.sh` files are executed before the function checks `dryRun`. Therefore, `--dry-run` is not a non-executing preview: it can run arbitrary code supplied by the target repository. The preflight sequence also calls `checkStaleBranches`, which can execute `git fetch --prune` before reaching the dry-run branch. This mutates remote-tracking state and performs network access despite the documented statement that a dry run makes no changes. ### Attack Path 1. A user obtains or inspects an u ...[truncated 700 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
core.mjs:1773
Finding

Automatic Execution of Repository-Controlled Deployment Scripts

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
core.mjs:2229
Finding

Failed npm Publication Can Destroy Unrelated Working-Tree Changes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
core.mjs:1198
Finding

Path Traversal in Website Publication Target Name

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
core.mjs:1056
Finding

Predictable Release-Notes Temporary File Permits Symlink Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
core.mjs:260
Finding

npm Authentication Token Exposed in Child-Process Arguments

Content
View full analysis
/dev/null`, { encoding: 'utf8' } ).trim(); ``` ### Technical Analysis The 1Password retrieval is consistent with the declared publishing functionality, and the observed destination is the official npm registry. No unknown credential-exfiltration endpoint was identified. However, the npm token is embedded directly in the child process argument vector. Error-message redaction only protects generated logs; it does not remove the secret from process metadata. Depending on the operating system, other processes running as the same user or with elevated inspection privileges may observe command-line arguments while npm is running. ### Attack Path 1. A local malicious process monitors newly created processes or process argument data. 2. The user invokes npm publication through the release tool. 3. The tool starts npm with `_authToken=` in its arguments. 4. The monitoring process captures the argument before npm exits. 5. The attacker reuses the token against ...[truncated 269 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (21)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · CHANGELOG.md (reported line 36)May include surrounding context.

md
- `release()` ... full pipeline: bump, changelog, skill sync, commit, tag, publish
- `detectCurrentVersion()` ... read version from package.json
- `syncSkillVersion()` ... update SKILL.md frontmatter
- `updateChangelog()` ... prepend version entry
- `publishNpm()` ... npm publish via 1Password
- `publishGitHubPackages()` ... GitHub Packages publish

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · core.mjs (reported line 2134)May include surrounding context.

js
- `release()` ... full pipeline: bump, changelog, skill sync, commit, tag, publish
- `detectCurrentVersion()` ... read version from package.json
- `syncSkillVersion()` ... update SKILL.md frontmatter
- `updateChangelog()` ... prepend version entry
- `publishNpm()` ... npm publish via 1Password
- `publishGitHubPackages()` ... GitHub Packages publish

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises a one-command pipeline that performs version bumps, changelog and skill-file updates, commits, tags, pushes, npm publishing, GitHub Packages publishing, and GitHub release creation, but it does not prominently warn about these repository and publication side effects. In a skill context, this is dangerous because an agent or user may treat the tool as routine automation and unintentionally trigger irreversible external actions affecting source control, package registries, and public releases.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · REFERENCE.md (reported line 159)May include surrounding context.

md
## Auth

npm token is fetched from 1Password at publish time. No `.npmrc` files stored. No credentials in repos.

Requires:
- `op` CLI installed and configured

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · REFERENCE.md (reported line 236)May include surrounding context.

md
| `detectCurrentVersion(repoPath)` | Read version from package.json |
| `bumpSemver(version, level)` | Bump a semver string (patch/minor/major) |
| `bumpPrerelease(version, track)` | Bump a prerelease version (alpha/beta) |
| `syncSkillVersion(repoPath, newVersion)` | Update SKILL.md frontmatter |
| `updateChangelog(repoPath, newVersion, notes)` | Prepend to CHANGELOG.md |
| `publishNpm(repoPath)` | Publish to npmjs.com (@latest) |
| `publishNpmWithTag(repoPath, tag)` | Publish to npmjs.com with specific tag |

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · core.mjs (reported line 733)May include surrounding context.

js
| `detectCurrentVersion(repoPath)` | Read version from package.json |
| `bumpSemver(version, level)` | Bump a semver string (patch/minor/major) |
| `bumpPrerelease(version, track)` | Bump a prerelease version (alpha/beta) |
| `syncSkillVersion(repoPath, newVersion)` | Update SKILL.md frontmatter |
| `updateChangelog(repoPath, newVersion, notes)` | Prepend to CHANGELOG.md |
| `publishNpm(repoPath)` | Publish to npmjs.com (@latest) |
| `publishNpmWithTag(repoPath, tag)` | Publish to npmjs.com with specific tag |

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · core.mjs (reported line 2000)May include surrounding context.

js
| `detectCurrentVersion(repoPath)` | Read version from package.json |
| `bumpSemver(version, level)` | Bump a semver string (patch/minor/major) |
| `bumpPrerelease(version, track)` | Bump a prerelease version (alpha/beta) |
| `syncSkillVersion(repoPath, newVersion)` | Update SKILL.md frontmatter |
| `updateChangelog(repoPath, newVersion, notes)` | Prepend to CHANGELOG.md |
| `publishNpm(repoPath)` | Publish to npmjs.com (@latest) |
| `publishNpmWithTag(repoPath, tag)` | Publish to npmjs.com with specific tag |

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

After creating a GitHub release, the code automatically extracts every #number from the release body and attempts to close matching issues on the public repository. Because release notes are user-controlled text, this can trigger unintended issue closure and workflow manipulation without explicit approval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill executes external deployment scripts such as deploy.sh and deploy-public.sh from repository-controlled paths as part of release publishing. That allows arbitrary code execution with the operator's local privileges and credentials, which is broader and riskier than the stated one-command publish workflow suggests.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README gives broad natural-language activation guidance that tells an agent to read repository files and then continue an interactive workflow, but it does not clearly define safe activation boundaries or require explicit confirmation before any later release-related actions. In an agentic environment, vague trigger phrasing can cause the skill to be invoked during generic repository-analysis requests and increase the chance that higher-risk release automation is introduced into the session without the user fully intending it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill markets itself as a 'one-command release pipeline' and examples show wip-release patch as the default path, but the description does not clearly warn that this performs version bumping, tagging, pushing, npm publication, GitHub release creation, and possibly other side effects by default. In an agent-executed context, missing an explicit irreversible-actions warning increases the chance of accidental supply-chain changes from a casual or mistaken invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill describes automatically copying SKILL.md into another repository and executing that repo's deploy.sh, while framing failures as non-blocking, but it does not give a strong caution that this crosses repository boundaries and runs arbitrary deployment logic. In a security-sensitive agent environment, that behavior expands the trust boundary and can lead to unintended code execution, data publication, or deployment to a live website if the configured website repo is wrong or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool closes issues automatically after release creation without explicit warning or confirmation, so a release action has hidden workflow side effects beyond publishing artifacts. This is especially risky because issue numbers are inferred from release-body text rather than selected deliberately by the operator.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says it publishes to npm and GitHub, but this code also publishes SKILL content to ClawHub and copies it into a separate website repository before invoking deployment to a VPS. That is materially broader behavior than the declared purpose, which increases the chance of unintended data disclosure or unauthorized external publication during a release run.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Website publication and deployment happen automatically when configuration or environment variables are present, without a user-facing confirmation at execution time. In a release tool, silent external publication is risky because operators may not realize content is being copied to another repo and deployed to a VPS.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code retrieves a GitHub auth token via gh auth token and immediately uses it to publish a package to GitHub Packages. The operation is safety-relevant because it accesses credentials and performs a network publish, but there is no visible prompt, warning, or user-facing log in this function explaining that token access and publication are happening.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Beyond releasing artifacts, the tool renames and deletes branches, prunes remote branches, removes worktrees, and writes local state markers. While not inherently malicious, these side effects exceed a narrow 'release pipeline' expectation and can cause unintended repository maintenance actions when users think they are only publishing a release.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The package description explicitly advertises a one-command workflow that bumps versions, modifies changelogs and SKILL.md, and publishes to npm and GitHub, but provides no warning in the manifest about these being high-impact, state-changing operations. In an agent skill context, this increases the risk of accidental invocation leading to unintended file modifications or releases, especially if a caller treats the package as routine tooling rather than a privileged release actuator.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
77% confidence
Finding

The dependency is specified with a caret range (^1.0.0), allowing installation of newer semver-compatible releases without explicit review or reproducibility guarantees. For a release automation tool that may run in privileged CI or developer environments, this can unexpectedly pull in vulnerable or behavior-changing code and expand supply-chain risk.

Content

Scanner excerpt · package.json (reported line 34)May include surrounding context.

json
},
  "homepage": "https://github.com/wipcomputer/wip-ai-devops-toolbox",
  "dependencies": {
    "@modelcontextprotocol/sdk": "^1.0.0"
  }
}

Unverifiable Dependency: @modelcontextprotocol/sdk has 3 known advisory(ies) (CVE-2026-25536 (@modelcontextprotocol/sdk has cross-client data leak via shared server/transport); CVE-2026-0621 (Anthropic's MCP TypeScript SDK has a ReDoS vulnerability); CVE-2025-66414 (Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protec)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
81% confidence
Finding

The manifest depends on @modelcontextprotocol/sdk without pinning an exact version, while the package family has known advisories including data leak, ReDoS, and DNS rebinding-related issues. Because the actual installed version is not fixed, consumers cannot verify whether they are exposed, and this uncertainty is more concerning in an agent-integrated release tool that may process sensitive repository or credentialed publishing workflows.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
core.mjs:227