Back to skill

Security audit

repo-standardizer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed GitHub repository standardizer with real write authority, but its behavior fits that purpose and includes user-control guardrails.

Install only if you want an agent to make live repository-configuration changes. Review the dry-run carefully, use the least-privileged GitHub credential that can perform the requested modules, and inspect generated CI/ruleset/AGENTS.md/CLAUDE.md files before pushing them to important repositories.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
templates/ci-node.yml:12
Finding

Generated CI Workflows Use Mutable Actions and Unpinned Dependencies

Content
View full analysis
Remediation
View remediation
# v4.x.x - uses: actions/setup-node@ # v4.x.x ``` Retain the release version in a comment for maintainability. 2. Use a controlled update mechanism such as Dependabot or Renovate to propose reviewed action-SHA updates. 3. Pin Node package-manager versions in the repository's `package.json`: ```json { "packageManager": "pnpm@" } ``` Then enable and use Corepack rather than globally installing the latest package: ```yaml - run: corepack enable ``` 4. Require a supported lockfile and fail closed when none exists. Avoid the unrestricted `npm install` fallback in standardized CI. 5. For Python, generate and commit a lockfile with fully resolved versions. Where practical, use hash verification: ```bash pip install --require-hashes -r requirements-dev.lock pip install --no-deps -e . ``` 6. Review installation and build hooks because dependency installation can execute project-controlled or package-controlled code. 7. Combine dependency pinning with explicit read-only workflow permissions to limit the impact of any future supply-chain compromise. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
templates/ci-node.yml:1
Finding

Generated CI Workflows Do Not Declare Least-Privilege Token Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation examples use very broad phrases like 'standardize', 'tidy up', and 'professionalize this repo', which can cause the skill to trigger in situations where the user did not clearly authorize repository-wide administrative changes. Because this skill can modify labels, workflows, rulesets, and documentation on live repositories, accidental invocation could lead to unintended writes to sensitive repos.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 379)May include surrounding context.

md
- Ask the user: which languages should the README support? (suggest the
  project's primary language + English for international projects)
- If a README already exists, ask whether to adapt it into more languages —
  never add languages without asking.
- Language switcher convention (pattern from `programmingHLS/ccmm`):
  - Default file stays `README.md` (usually English).
  - Extra languages: `README.<lang>.md` (e.g. `README.zh.md`, `README.ja.md`).

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The line contains a placeholder for a language requirement, which can be interpreted or filled in as a mandatory language/locale constraint for the skill. Because no user choice, opt-in, or documented justification is provided, this creates a natural-language policy risk under the language/locale policy rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The line specifies i18n: <language requirement, if any>, which encourages authors to impose a language requirement in the skill template. Because it does not mention user opt-in, language choice, or a documented justification for any locale restriction, it can lead to skills that force a specific language and violate the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L06 states 'Write labels in the repo's primary language,' which imposes a language requirement as a blanket rule. The file does not indicate any opt-in, alternative locale support, or justification for the constraint, matching the policy-violation category for forced language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file is written as a Chinese-language template and the language switch line marks Simplified Chinese as the active version, but there is no statement that language is user-selectable or that the locale restriction is required. Under the policy rule, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.