Back to skill

Security audit

oss-scaffold

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a repository scaffolder, but some bundled CI templates add release and package-publishing automation that is broader than the skill’s stated simple CI purpose.

Review or remove the generated publish/release jobs before pushing the scaffolded repository, especially any workflow using NPM_TOKEN, GITHUB_TOKEN, contents: write, or id-token: write. Use the skill only when you want a new repository scaffold and local git commit created.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (28)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates/changelog.md (reported line 1)May include surrounding context.

md
<!-- CHANGELOG 模板。骨架+占位符;条目风格按 oss-voice §4(一行一条、面向用户效果、破坏性变更入 Breaking Changes)执行,不在此复制。 -->

# Changelog

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates/changelog.md (reported line 1)May include surrounding context.

md
<!-- CHANGELOG 模板。骨架+占位符;条目风格按 oss-voice §4(一行一条、面向用户效果、破坏性变更入 Breaking Changes)执行,不在此复制。 -->

# Changelog

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates/gitignore-go.md (reported line 1)May include surrounding context.

md
<!-- .gitignore 模板:Go 版。实例化时去掉本注释行,内容原样落盘 .gitignore。 -->

# Binaries
*.exe

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates/gitignore-go.md (reported line 1)May include surrounding context.

md
<!-- .gitignore 模板:Go 版。实例化时去掉本注释行,内容原样落盘 .gitignore。 -->

# Binaries
*.exe

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/templates/gitignore-go.md (reported line 22)May include surrounding context.

md
go.work.sum

# Environment
.env
.env.*
!.env.example

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/templates/gitignore-node.md (reported line 23)May include surrounding context.

md
go.work.sum

# Environment
.env
.env.*
!.env.example

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/templates/gitignore-python.md (reported line 30)May include surrounding context.

md
go.work.sum

# Environment
.env
.env.*
!.env.example

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates/gitignore-node.md (reported line 1)May include surrounding context.

md
<!-- .gitignore 模板:Node.js 版。实例化时去掉本注释行,内容原样落盘 .gitignore。 -->

# Dependencies
node_modules/

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates/gitignore-node.md (reported line 1)May include surrounding context.

md
<!-- .gitignore 模板:Node.js 版。实例化时去掉本注释行,内容原样落盘 .gitignore。 -->

# Dependencies
node_modules/

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates/gitignore-python.md (reported line 1)May include surrounding context.

md
<!-- .gitignore 模板:Python 版。实例化时去掉本注释行,内容原样落盘 .gitignore。 -->

# Byte-compiled
__pycache__/

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates/gitignore-python.md (reported line 1)May include surrounding context.

md
<!-- .gitignore 模板:Python 版。实例化时去掉本注释行,内容原样落盘 .gitignore。 -->

# Byte-compiled
__pycache__/

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises broad trigger phrases such as “初始化组件” and “scaffold”, which are generic enough to match many ordinary repository or project-setup requests. That can cause the skill to activate outside its intended scope and perform repository-initialization actions, including local git operations and preparation for GitHub publication, when a more specific or safer skill should have been chosen.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest says the skill generates a "CI 骨架" as part of repository scaffolding, but this workflow also embeds a tag-triggered packaging/release flow that archives source and prepares release artifacts. Packaging for releases is a broader delivery capability than a basic CI skeleton and is not clearly claimed in the manifest description.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This CI skeleton includes a release-capable publish-npm job with elevated permissions (contents: write, id-token: write) and a direct npm publish action, which goes beyond a normal test/build workflow. In a scaffolding skill that claims to generate repository components automatically, embedding release automation by default increases the chance of unintended package publication, misuse of secrets, or exposing consumers to a supply-chain event if the generated repository is pushed without careful review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment states "默认英文" (default English), which is a natural-language locale policy embedded in the file. Per the policy criteria, forcing a specific language without user opt-in or a documented justification is a violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This file contains natural-language contribution policy content and effectively centers a specific language without documenting user choice or opt-in. Under the language/locale policy rule, a skill should not impose a language expectation unless it clearly offers alternatives or justifies the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing natural language content only in Chinese, including the title, section headings, and conclusions. Under the policy rules, forcing a specific language without user opt-in can be a locale-policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file content is written entirely in Chinese and does not indicate that another language is available or that Chinese is required for a region-specific or compliance-specific reason. Under the language/locale policy rule, forcing a single language without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file’s descriptive comments are written in Chinese, including the title and operational notes, which imposes a specific language in natural-language content without offering any alternative or indicating a region-specific requirement. This matches the language/locale policy concern for natural-language text embedded in configuration files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file contains Chinese-only natural-language comments describing the workflow context, such as the title and operational notes, with no indication that language selection is optional or that the workflow is region-specific. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language comments at L01-L02 are written entirely in Chinese, which indicates a fixed language choice in the template context. The file does not provide any user opt-in, alternative locale, or justification that this workflow template is intended only for a Chinese-language audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The comment states "默认英文" (default English), which imposes a language default in natural-language guidance. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The comment on L01 includes '默认英文' ('default English'), which indicates the template is intended to default to a specific language. Under the policy, forcing or defaulting to a language without explicit user opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.