Back to skill

Security audit

Gitea

Security checks for vulnerabilities and agentic risk

Overview

This Gitea CLI skill is mostly coherent, but it should be reviewed because it combines repository/API access with under-disclosed token handling, secret-related commands, and a mutable CLI dependency.

Review before installing if you will use this with private repositories or CI/CD administration. Prefer a pinned tea version, use least-privilege and short-lived Gitea tokens, avoid pasting real tokens into chat or shell history, and treat Actions secrets and tea api commands as sensitive administrative operations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned Tea CLI Dependency Uses a Mutable Latest Version

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19–25
Vulnerability Type: Supply-chain risk caused by an unpinned executable dependency
Risk Level: Medium

Vulnerable Code Snippet:

yaml
          {
            "id": "go",
            "kind": "go",
            "module": "code.gitea.io/tea@latest",
            "bins": ["tea"],
            "label": "Install Tea CLI (go)",
          },

Technical Analysis

The Go installation definition requests code.gitea.io/tea@latest. The latest identifier is mutable, so the version installed in the future may differ from the version reviewed when this Skill was published. Consequently, the effective executable dependency cannot be reproduced or independently verified from the Skill definition.

This is a supply-chain weakness rather than evidence that the current upstream package is malicious. Exploitation would require an attacker to compromise the upstream project, its release process, the module distribution channel, or another trusted component involved in resolving the latest version.

Attack Path

  1. An attacker compromises the upstream Tea project, release credentials, or relevant package distribution infrastructure.
  2. The attacker publishes a malicious version that becomes the version resolved by @latest.
  3. A user or agent installs the dependency through the Skill's Go installation definition.
  4. The malicious Tea binary executes when the Skill invokes tea.
  5. The binary operates with the privileges and environment access of the user running the agent.

Impact Assessment

A compromised dependency could execute arbitrary code with the invoking user's privileges. Depending on the execution environment, it could access local files, environment variables, Gitea credentials, repository contents, and network resources available to that user. It could also alter repository operations performed through the CLI. This finding do ...[truncated 73 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace code.gitea.io/tea@latest with a specific, reviewed release such as code.gitea.io/tea@vX.Y.Z.
  • Establish a controlled update process that reviews release notes and security advisories before changing the pinned version.
  • Where the installation system supports it, verify downloaded artifacts using cryptographic checksums or signed release provenance.
  • Prefer trusted binary distribution channels with integrity verification and version pinning.
  • Periodically review the pinned version for disclosed vulnerabilities rather than relying on automatic resolution of the newest release.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:91
Finding

Gitea Access Token Supplied Directly as a Command-Line Argument

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 91–93
Vulnerability Type: Sensitive credential exposure through command-line arguments
Risk Level: Medium

Vulnerable Code Snippet:

bash
tea login add --name my-gitea --url https://gitea.example.com --token <your-token>

Technical Analysis

The documented login command instructs users to substitute a real Gitea access token directly into a shell command. Depending on the operating system, shell, terminal tooling, and automation environment, command-line secrets may be exposed through shell history, process inspection, command auditing, diagnostic output, CI logs, terminal recording, or telemetry.

Process-list exposure may exist only while the command is running, but shell histories and logs can retain the token after execution. The placeholder itself is not a credential; the vulnerability arises when the documented command is followed with a real token.

Attack Path

  1. A user replaces <your-token> with a valid Gitea token and runs the documented command.
  2. The shell records the command in history, an automation system logs it, or another local principal observes the process arguments.
  3. An attacker with access to the resulting history, logs, telemetry, or process metadata retrieves the token.
  4. The attacker submits the token to the configured Gitea instance.
  5. The attacker performs actions allowed by the token until it expires or is revoked.

Impact Assessment

The obtainable privileges are limited by the scopes assigned to the exposed token and the permissions of its associated Gitea account. Potential impact includes reading private repositories, accessing issue and pull-request data, modifying repository content, managing CI/CD metadata, or performing other API operations authorized by the token. Organization-wide or administrative impact is possible only if the exposed token already carries those elevated permi ...[truncated 7 chars]

Remediation
View remediation

Remediation Suggestions

  • Prefer Tea's interactive, non-echoing credential prompt when supported instead of placing the token in the command line.
  • If supported by Tea, obtain the token from a protected credential file, operating-system credential store, or secret manager.
  • For automation, inject credentials through the platform's masked-secret mechanism and ensure commands do not echo expanded values.
  • Avoid placing tokens in scripts, shell history, configuration examples, or process arguments.
  • Apply least-privilege scopes and short expiration periods to Gitea tokens.
  • Document immediate token revocation and rotation procedures for suspected exposure.
  • Treat shell-history suppression as defense in depth only, because it does not prevent exposure through process inspection or external logging.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly documents a command to list repository secrets, which normalizes access to highly sensitive material without any warning, access-control context, or guidance to avoid exposing values in logs or chat output. In an agent skill context, this increases the chance that an automated workflow or user will retrieve sensitive CI/CD secrets unnecessarily, potentially leading to credential disclosure or downstream compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation shows token-based login setup using a raw command-line argument placeholder but provides no warning about secure credential handling, token scope minimization, shell history exposure, or secret storage. In practice, users may paste real tokens directly into commands, causing them to be exposed via terminal history, process listings, transcripts, or agent logs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.