Back to skill

Security audit

golang-context

Security checks for vulnerabilities and agentic risk

Overview

This Go context helper is mostly ordinary guidance, but it requests broad git and agent permissions beyond what its stated purpose needs.

Install only if you are comfortable with a Go guidance skill that can edit project files and, depending on host enforcement, may also have broad git and delegation capability. Prefer a version with git access narrowed to read-only commands or removed, and Agent access removed unless you explicitly need delegation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:18
Finding

Overly Broad Tool Permissions Violate Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 18
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Medium

Vulnerable Code:

yaml
allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent

Technical Analysis

The skill grants unrestricted Bash(git:*) access and the general-purpose Agent capability. Its documented purpose is limited to reviewing and improving Go context.Context usage, for which file inspection, editing, Go commands, and linting are sufficient.

Broad Git access can modify repository state, configuration, branches, remotes, hooks, or tracked content, depending on the execution environment. The Agent permission may also permit delegation that expands the effective action surface beyond the immediate context-analysis task. Neither capability is required by the documented workflows.

This violates the principle of least privilege. Although the reviewed skill contains no explicit instruction to abuse these permissions, unnecessary capabilities increase the consequences of malicious or misleading repository content encountered while the skill is active.

Attack Path

  1. An attacker places adversarial or misleading instructions in repository content that the skill is asked to inspect.
  2. The agent reads that content while operating with the permissions declared in allowed-tools.
  3. The content induces the agent to invoke an unnecessary git operation or delegate work through Agent.
  4. The resulting operation may alter repository state, inspect Git configuration, manipulate remotes, or perform delegated actions outside the skill’s legitimate context-review scope.
  5. These actions occur with permissions that would not have been available under a narrowly scoped tool policy.

This is a conditional exploitation path: successful abuse depends on the host agent honoring the declared permissions and bein ...[truncated 500 chars]

Remediation
View remediation

Remediation Suggestions

Apply a least-privilege tool policy:

  1. Remove Bash(git:*) unless a specific, documented Git operation is essential.
  2. Remove Agent unless delegation is necessary for a defined workflow.
  3. Retain only the capabilities needed for the stated task, such as:
    yaml
    allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*)
    
  4. Where supported by the host, constrain read and write access to the declared **/*.go path scope.
  5. If Git access later becomes necessary, allowlist individual read-only commands rather than the entire git:* command family.
  6. Require explicit user confirmation before repository-mutating operations or delegation outside the direct audit task.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The eval prompts are intentionally broad, open-ended code-generation tasks with only post-hoc assertions, and they do not constrain the model away from unsafe adjacent behaviors. In a skill/eval context, this can cause the agent to overgeneralize, produce insecure patterns outside the tested assertions, or trigger the skill in situations where its guidance is only partially applicable, increasing the chance of unsafe code suggestions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.