Back to skill

Security audit

Worktree Manager

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real local development worktree manager, but it has review-worthy safety gaps around destructive cleanup and shared MySQL access.

Review before installing in any repo with valuable local work, real data, or shared databases. Use only in disposable/local dev environments unless remove-worktree is hardened to fail closed without explicit confirmation, MYSQL_MAIN_DB is validated, and MySQL uses a non-default least-privilege credential.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
run.sh:75
Finding

Destructive worktree removal bypasses confirmation in non-interactive environments

Content
View full analysis
/dev/null && \ echo "Banco $DB removido." fi if [ -d "$WORKTREE_PATH" ]; then git worktree remove "$WORKTREE_PATH" --force 2>/dev/null || rm -rf "$WORKTREE_PATH" git worktree prune echo "Worktree removido: $WORKTREE_PATH" else echo "Worktree não encontrado: $WORKTREE_PATH" fi if [ -f "$ENV_FILE" ]; then rm "$ENV_FILE" echo "Env removido: $ENV_FILE" fi ``` ### Technical Analysis `confirm_destructive` only requests confirmation when standard input is attached to a terminal. If `[ -t 0 ]` is false, the function reaches its end and implicitly returns success. Consequently, non-interactive execution bypasses confirmation rather than failing closed. This behavior conflicts with the documented requirement ...[truncated 1628 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
run.sh:128
Finding

SQL injection through unvalidated MYSQL_MAIN_DB configuration

Content
View full analysis
/dev/null || echo 0) if [ "$table_count" -gt 0 ]; then ``` ### Technical Analysis The destination database is checked by `validate_db_name`, but `MYSQL_MAIN_DB` is not. The environment-controlled value is inserted inside a single-quoted SQL literal passed to `mysql -e`. An attacker who can influence the script's environment can insert a quote, terminate the original query, and append another SQL statement. For example, a value structurally equivalent to the following can close the `table_schema` literal and introduce another statement: ```text codai_main'; DROP DATABASE target_database; -- ``` The resulting SQL is executed using the MySQL root account. A later arithmetic error caused by unexpected command output would not undo an injected SQL statement that has already been executed. This is SQL injection rather than shell injection: shell metacharacters inside the expanded variable remain part of the already parsed double-quoted shell argument, but SQL metacharacters are interpreted by the MySQL server. ### Attack Path 1. Obtain the ability to set environment variables for a script invocation, CI job, development shell, or agent execution context. 2. Set `MYSQL_MAIN_DB` to a value containing a closing quote and an additional SQL statement. 3. Ensure the ...[truncated 1212 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
run.sh:31
Finding

Hardcoded MySQL root password fallback and credential exposure in process arguments

Content
View full analysis
/dev/null } dump_main_to() { local dest_db="$1" validate_db_name "$dest_db" local table_count table_count=$(docker exec "$MYSQL_CONTAINER" mysql -uroot -p"$MYSQL_ROOT_PASS" -sN \ -e "SELECT COUNT(*) FROM information_schema.tables WHERE table_schema='$MYSQL_MAIN_DB';" 2>/dev/null || echo 0) if [ "$table_count" -gt 0 ]; then echo "Copiando $MYSQL_MAIN_DB → $dest_db..." docker exec "$MYSQL_CONTAINER" \ mysqldump -uroot -p"$MYSQL_ROOT_PASS" "$MYSQL_MAIN_DB" | \ docker exec -i "$MYSQL_CONTAINER" \ mysql -uroot -p"$MYSQL_ROOT_PASS" "$dest_db" ``` The same pattern is used for deletion: ```bash if mysql_running; then docker exec "$MYSQL_CONTAINER" mysql -uroot -p"$MYSQL_ROOT_PASS" \ -e "DROP DATABASE IF EXISTS \`$DB\`;" 2>/dev/null && \ echo "Banco $DB removido." fi ``` ### Technical Analysis If neither `MYSQL_ROOT_PASSWORD` nor the compatibility variable `MYSQ ...[truncated 2276 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
73% confidence
Finding

The trigger 'start instance' overlaps semantically with common built-in 'start' behavior, creating a realistic risk of command shadowing or unintended skill invocation. In this skill's context, unintended invocation can start Docker services, create or seed databases, and modify local development infrastructure, so the effect is materially more dangerous than a harmless read-only action.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
71% confidence
Finding

The trigger 'stop instance' can conflict with a generic built-in 'stop' command, increasing the chance that a user's ordinary stop request is routed to this skill instead. Because this skill controls Docker containers and development instances, accidental invocation could disrupt running services and developer environments.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
75% confidence
Finding

'create worktree' collides with the common verb 'create', which can cause this skill to capture unrelated user requests. In context, accidental execution would alter the git repository state by creating branches, worktrees, and environment files, making the collision security-relevant because it changes local resources without clearly intended authorization.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger "start instance" is broad natural language that could overlap with ordinary requests in a development context, without clear scoping to this specific skill. The manifest lists trigger phrases but does not include exclusion conditions or context limits to distinguish when this skill should activate versus similar instance-management actions elsewhere.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger "stop instance" is a common administrative phrase and may collide with everyday developer requests unrelated to this skill. No contextual qualifier or exclusion guidance is provided to limit activation to Docker/git worktree instance management.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
70% confidence
Finding

'list instances' may shadow a built-in 'list' command, though the impact is lower because the documented action is primarily informational. Even so, unintended invocation could disclose local environment topology, container status, and related infrastructure details to a user who did not mean to query this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The trigger "create worktree" is reasonably domain-oriented but still broad enough to overlap with general git assistance requests, especially because the skill also manages Docker, databases, and proxy configuration. The manifest does not state boundaries for when this trigger should invoke this specific automation versus simple git worktree help.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger "remove worktree" is broad and could match routine git support requests, while this skill performs additional destructive actions including database deletion and environment cleanup. The manifest lacks scope constraints or negative examples to prevent accidental invocation in less destructive contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script's descriptive comments, usage text, warnings, and runtime messages are written in Portuguese, which imposes a specific language on users. The file does not offer any language selection or explain that the skill is intentionally limited to a Portuguese-speaking audience or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file hard-codes both English and Portuguese trigger phrases, but does not explain language selection or whether users can choose their preferred locale. This can conflict with organizational language/locale policies when a skill implicitly enforces or assumes supported languages without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.