T09 · Insecure Skill Coding Practices
- Location
core.mjs:2505- Finding
Shell Command Injection Through Git Branch or Worktree Names
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real release automation skill, but it can publish packages and releases, run repository deployment scripts, and perform cleanup actions with guardrails that are too broad for automatic agent use.
Install only if you intend to give this skill release authority over trusted repositories and authenticated publishing accounts. Run it from clean, backed-up working trees, review configured deploy scripts and website paths first, prefer dry-run only on trusted repos, and avoid using broad npm/GitHub credentials until the rollback, script-execution, and confirmation gaps are fixed.
core.mjs:2505Shell Command Injection Through Git Branch or Worktree Names
core.mjs:2037Dry-Run Mode Executes Repository-Controlled Scripts
core.mjs:1773Automatic Execution of Repository-Controlled Deployment Scripts
core.mjs:2229Failed npm Publication Can Destroy Unrelated Working-Tree Changes
core.mjs:1198Path Traversal in Website Publication Target Name
core.mjs:1056Predictable Release-Notes Temporary File Permits Symlink Overwrite
core.mjs:260npm Authentication Token Exposed in Child-Process Arguments
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- `release()` ... full pipeline: bump, changelog, skill sync, commit, tag, publish
- `detectCurrentVersion()` ... read version from package.json
- `syncSkillVersion()` ... update SKILL.md frontmatter
- `updateChangelog()` ... prepend version entry
- `publishNpm()` ... npm publish via 1Password
- `publishGitHubPackages()` ... GitHub Packages publish
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- `release()` ... full pipeline: bump, changelog, skill sync, commit, tag, publish
- `detectCurrentVersion()` ... read version from package.json
- `syncSkillVersion()` ... update SKILL.md frontmatter
- `updateChangelog()` ... prepend version entry
- `publishNpm()` ... npm publish via 1Password
- `publishGitHubPackages()` ... GitHub Packages publish
The README advertises a one-command pipeline that performs version bumps, changelog and skill-file updates, commits, tags, pushes, npm publishing, GitHub Packages publishing, and GitHub release creation, but it does not prominently warn about these repository and publication side effects. In a skill context, this is dangerous because an agent or user may treat the tool as routine automation and unintentionally trigger irreversible external actions affecting source control, package registries, and public releases.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Auth
npm token is fetched from 1Password at publish time. No `.npmrc` files stored. No credentials in repos.
Requires:
- `op` CLI installed and configured
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
| `detectCurrentVersion(repoPath)` | Read version from package.json |
| `bumpSemver(version, level)` | Bump a semver string (patch/minor/major) |
| `bumpPrerelease(version, track)` | Bump a prerelease version (alpha/beta) |
| `syncSkillVersion(repoPath, newVersion)` | Update SKILL.md frontmatter |
| `updateChangelog(repoPath, newVersion, notes)` | Prepend to CHANGELOG.md |
| `publishNpm(repoPath)` | Publish to npmjs.com (@latest) |
| `publishNpmWithTag(repoPath, tag)` | Publish to npmjs.com with specific tag |
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
| `detectCurrentVersion(repoPath)` | Read version from package.json |
| `bumpSemver(version, level)` | Bump a semver string (patch/minor/major) |
| `bumpPrerelease(version, track)` | Bump a prerelease version (alpha/beta) |
| `syncSkillVersion(repoPath, newVersion)` | Update SKILL.md frontmatter |
| `updateChangelog(repoPath, newVersion, notes)` | Prepend to CHANGELOG.md |
| `publishNpm(repoPath)` | Publish to npmjs.com (@latest) |
| `publishNpmWithTag(repoPath, tag)` | Publish to npmjs.com with specific tag |
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
| `detectCurrentVersion(repoPath)` | Read version from package.json |
| `bumpSemver(version, level)` | Bump a semver string (patch/minor/major) |
| `bumpPrerelease(version, track)` | Bump a prerelease version (alpha/beta) |
| `syncSkillVersion(repoPath, newVersion)` | Update SKILL.md frontmatter |
| `updateChangelog(repoPath, newVersion, notes)` | Prepend to CHANGELOG.md |
| `publishNpm(repoPath)` | Publish to npmjs.com (@latest) |
| `publishNpmWithTag(repoPath, tag)` | Publish to npmjs.com with specific tag |
After creating a GitHub release, the code automatically extracts every #number from the release body and attempts to close matching issues on the public repository. Because release notes are user-controlled text, this can trigger unintended issue closure and workflow manipulation without explicit approval.
The skill executes external deployment scripts such as deploy.sh and deploy-public.sh from repository-controlled paths as part of release publishing. That allows arbitrary code execution with the operator's local privileges and credentials, which is broader and riskier than the stated one-command publish workflow suggests.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The README gives broad natural-language activation guidance that tells an agent to read repository files and then continue an interactive workflow, but it does not clearly define safe activation boundaries or require explicit confirmation before any later release-related actions. In an agentic environment, vague trigger phrasing can cause the skill to be invoked during generic repository-analysis requests and increase the chance that higher-risk release automation is introduced into the session without the user fully intending it.
The skill markets itself as a 'one-command release pipeline' and examples show wip-release patch as the default path, but the description does not clearly warn that this performs version bumping, tagging, pushing, npm publication, GitHub release creation, and possibly other side effects by default. In an agent-executed context, missing an explicit irreversible-actions warning increases the chance of accidental supply-chain changes from a casual or mistaken invocation.
The skill describes automatically copying SKILL.md into another repository and executing that repo's deploy.sh, while framing failures as non-blocking, but it does not give a strong caution that this crosses repository boundaries and runs arbitrary deployment logic. In a security-sensitive agent environment, that behavior expands the trust boundary and can lead to unintended code execution, data publication, or deployment to a live website if the configured website repo is wrong or compromised.
The tool closes issues automatically after release creation without explicit warning or confirmation, so a release action has hidden workflow side effects beyond publishing artifacts. This is especially risky because issue numbers are inferred from release-body text rather than selected deliberately by the operator.
The skill description says it publishes to npm and GitHub, but this code also publishes SKILL content to ClawHub and copies it into a separate website repository before invoking deployment to a VPS. That is materially broader behavior than the declared purpose, which increases the chance of unintended data disclosure or unauthorized external publication during a release run.
Website publication and deployment happen automatically when configuration or environment variables are present, without a user-facing confirmation at execution time. In a release tool, silent external publication is risky because operators may not realize content is being copied to another repo and deployed to a VPS.
This code retrieves a GitHub auth token via gh auth token and immediately uses it to publish a package to GitHub Packages. The operation is safety-relevant because it accesses credentials and performs a network publish, but there is no visible prompt, warning, or user-facing log in this function explaining that token access and publication are happening.
Beyond releasing artifacts, the tool renames and deletes branches, prunes remote branches, removes worktrees, and writes local state markers. While not inherently malicious, these side effects exceed a narrow 'release pipeline' expectation and can cause unintended repository maintenance actions when users think they are only publishing a release.
The package description explicitly advertises a one-command workflow that bumps versions, modifies changelogs and SKILL.md, and publishes to npm and GitHub, but provides no warning in the manifest about these being high-impact, state-changing operations. In an agent skill context, this increases the risk of accidental invocation leading to unintended file modifications or releases, especially if a caller treats the package as routine tooling rather than a privileged release actuator.
The dependency is specified with a caret range (^1.0.0), allowing installation of newer semver-compatible releases without explicit review or reproducibility guarantees. For a release automation tool that may run in privileged CI or developer environments, this can unexpectedly pull in vulnerable or behavior-changing code and expand supply-chain risk.
},
"homepage": "https://github.com/wipcomputer/wip-ai-devops-toolbox",
"dependencies": {
"@modelcontextprotocol/sdk": "^1.0.0"
}
}
The manifest depends on @modelcontextprotocol/sdk without pinning an exact version, while the package family has known advisories including data leak, ReDoS, and DNS rebinding-related issues. Because the actual installed version is not fixed, consumers cannot verify whether they are exposed, and this uncertainty is more concerning in an agent-integrated release tool that may process sensitive repository or credentialed publishing workflows.
Detected: suspicious.dangerous_exec