Back to skill

Security audit

release-checker

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent release-checking tool, but it has an unsafe branch argument path that can execute unintended shell commands.

Install only if you trust the maintainer and can review or patch the script first. Do not pass branch names from untrusted text; a crafted --branch value could run shell commands. Prefer pinning sqlglot, using a disposable workspace, and checking all report and SQL output paths before running conversion or batch mode.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/release_checker.py:613
Finding

Shell Command Injection Through User-Controlled Git Branch Argument

Content
View full analysis
--name-status ``` 4. `subprocess.run()` executes the string with `shell=True`. 5. The shell interprets injected metacharacters and executes the attacker-selected command. 6. The injected command inherits the Skill process's filesystem access, environment, network access, and other operating-system permissions. A representati ...[truncated 1126 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/requirements.txt:3
Finding

Unbounded Third-Party Dependency Version Allows Unreviewed Future Releases

Content
View full analysis
=20.0.0 ``` ### Technical Analysis The dependency declaration establishes a minimum version but no upper bound or exact audited version. A future installation can therefore resolve to any later `sqlglot` release available from the configured package index. This does not demonstrate that the current `sqlglot` package is malicious. The risk is that installations are not reproducible and may automatically adopt a future compromised, behaviorally incompatible, or insufficiently reviewed release. The script imports the package during startup, so code distributed by the resolved package executes in the Skill process. The documentation also advises users to run `pip install sqlglot`, which may resolve the newest available release rather than a version reviewed with this project. ### Attack Path 1. The Skill is installed in a new or refreshed environment. 2. The package installer evaluates `sqlglot>=20.0.0`. 3. The installer selects a later release based on the mutable state of the configured package index. 4. The selected package is installed without a project-provided hash or lock-file integrity check. 5. `release_checker.py` imports `sqlglot`. 6. Code from the resolved package executes with the permissions of the Skill process. 7. If that future package release or package-distribution channel is compromised, malicious code could access resources available to the process. ### Impact Assessment The potential scope is equivalent to the permissions of the Python process importing the dependency. A compromised dependency could theoretically: - Read or alter project files and generated SQL. - Access environment variables and other process-readable information. - Manipulate conversion results or reports. - Use available network ...[truncated 318 chars]
Remediation
View remediation
``` For stronger supply-chain integrity: 1. Generate a lock file containing exact transitive dependency versions. 2. Record package hashes and install with hash verification: ```bash python -m pip install --require-hashes -r requirements.txt ``` 3. Use an approved package index or internal dependency mirror. 4. Review dependency updates before changing the pinned version. 5. Run dependency vulnerability and provenance checks in continuous integration. 6. Document the supported Python and `sqlglot` versions. 7. Replace generic installation guidance such as `pip install sqlglot` with installation from the project's locked requirements file. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (25)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
---
name: release-checker
description: "一体化发版兼容性检查工具。自动分析 Git diff 检测发版兼容性,通过代码智能识别推送中心/Gateway/配置变更,自动检测 SQL 脚本兼容性并生成多数据库版本,输出完整的 TODO 清单和 Markdown 报告。"
category: development

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 238)May include surrounding context.

md
python scripts/release_checker.py \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 262)May include surrounding context.

md
python scripts/release_checker.py \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 265)May include surrounding context.

md
python scripts/release_checker.py \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 611)May include surrounding context.

md
python scripts/release_checker.py \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 752)May include surrounding context.

md
python scripts/release_checker.py \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The script builds a shell command using untrusted input (compare_branch) and executes it with shell=True. An attacker controlling the branch argument can inject shell metacharacters and execute arbitrary OS commands in the context of the user running the tool, which is especially dangerous in CI/CD or developer environments.

Content

Scanner excerpt · scripts/release_checker.py (reported line 618)May include surrounding context.

python
else:
                cmd = "git diff --name-status"
            
            result = subprocess.run(
                cmd,
                shell=True,
                cwd=self.project_path,

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/release_checker.py (reported line 655)May include surrounding context.

python
def _get_unstaged_changed_files(self) -> List[ChangeFile]:
        """Get unstaged changes as fallback"""
        try:
            result = subprocess.run(
                "git diff --name-status",
                shell=True,
                cwd=self.project_path,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The top-level description highlights analysis and report generation but does not clearly warn that the skill writes converted SQL files and Markdown reports to disk. This omission can mislead users into invoking the skill without realizing it may create or overwrite artifacts in the workspace, which is more dangerous because the skill also advertises automatic execution and output generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file defines activation conditions using broad phrases like 'user wants to analyze code and script changes in git diff' and 'user needs to generate release TODO list' without tight scope boundaries or negative examples for those phrases. Such wording can match many ordinary development requests and may cause the skill to activate outside the intended release-compatibility context.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.EN.md (reported line 278)May include surrounding context.

md
### Step 6.5: SQL Conversion Validation (Python Script Automatic Execution + Manual Confirmation)

**Python script automatically executes validation (10+ rules) after conversion to ensure generated SQL is executable.**

#### 6.5.1 Python Automatic Syntax Validation

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.EN.md (reported line 282)May include surrounding context.

md
### Step 6.5: SQL Conversion Validation (Python Script Automatic Execution + Manual Confirmation)

**Python script automatically executes validation (10+ rules) after conversion to ensure generated SQL is executable.**

#### 6.5.1 Python Automatic Syntax Validation

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.EN.md (reported line 534)May include surrounding context.

md
### Step 6.5: SQL Conversion Validation (Python Script Automatic Execution + Manual Confirmation)

**Python script automatically executes validation (10+ rules) after conversion to ensure generated SQL is executable.**

#### 6.5.1 Python Automatic Syntax Validation

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.EN.md (reported line 628)May include surrounding context.

md
### Step 6.5: SQL Conversion Validation (Python Script Automatic Execution + Manual Confirmation)

**Python script automatically executes validation (10+ rules) after conversion to ensure generated SQL is executable.**

#### 6.5.1 Python Automatic Syntax Validation

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.EN.md (reported line 748)May include surrounding context.

md
### Step 6.5: SQL Conversion Validation (Python Script Automatic Execution + Manual Confirmation)

**Python script automatically executes validation (10+ rules) after conversion to ensure generated SQL is executable.**

#### 6.5.1 Python Automatic Syntax Validation

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The batch-mode documentation explains per-project and global report generation but does not clearly warn that multiple files may be created or overwritten across several project paths. In batch mode this increases operational risk because a single invocation can fan out writes across many repositories or directories, amplifying accidental data loss or clutter.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L895 states 'Does not execute actual SQL validation', which directly conflicts with repeated claims elsewhere that the skill 'automatically executes validation' and runs 10+ PostgreSQL/Oracle syntax checks after conversion. This is an active documentation contradiction about what the skill does, not merely an omission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as a Chinese-language tool, with the rest of the document also prescribing prompts and interaction text only in Chinese. There is no indication that the user may choose another language or locale, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The limitations section states '不执行实际 SQL 验证' at L895, which tells users the skill does not validate SQL. However, the workflow and examples repeatedly state that the Python script automatically performs PostgreSQL/Oracle syntax validation after conversion (for example L276-L309, L628-L653, L690-L699). These statements create an intent/documentation contradiction about whether validation is actually performed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code defines user-facing labels, descriptions, and TODO templates entirely in Chinese, and the rest of the script prints and prompts in Chinese as well. For a general-purpose release-checking skill, that imposes a specific language/locale on users without offering a choice or documenting that the tool is intentionally region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script writes PostgreSQL and Oracle output files to disk in conversion mode, but there is no confirmation prompt before creating or overwriting those files. Although the script logs after saving, it does not disclose beforehand that running this mode will modify the filesystem, which is a safety-relevant operation for code files.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comments at L1393-L1395 and L1415-L1417 state that the script only shows file statistics and that release components will be provided later by the skill or user. However, the code immediately calls todo_generator.generate_todos(report) at L1425, and that generator reads report.release_components, which was never populated from user input or detector output. This is an active contradiction between the documented intent and the implemented behavior around component confirmation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The limitations section says '不执行 Java 代码编译验证' at L896, implying compile validation is out of scope for the skill itself. Yet the generated TODO example includes '执行单元测试: mvn test' and '编译验证: mvn compile' at L826-L827 as concrete prescribed actions in the skill flow/output, which blurs whether the skill only reports or actually performs these checks. This is a documentation-level inconsistency in stated intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The save_report method creates directories and writes a report file, but the code provides no confirmation prompt or advance disclosure that the specified path will be created or overwritten. This is a file-modifying operation, and the visible message appears only after the write succeeds.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The dependency is specified with a lower-bound version only (sqlglot>=20.0.0), which allows installation of any newer release, including unreviewed major versions. This can introduce supply-chain risk, unexpected behavior changes, or accidental uptake of a compromised or breaking release during future installs.

Content

Scanner excerpt · scripts/requirements.txt (reported line 3)May include surrounding context.

text
# Release Checker
# Dependencies:
sqlglot>=20.0.0
# No other external dependencies required

Static analysis

No suspicious patterns detected.