Back to skill

Security audit

golang-popular-libraries

Security checks for vulnerabilities and agentic risk

Overview

This Go library recommendation skill is not malicious, but it asks for more file-editing, command, Git, and delegation authority than its advisory purpose needs.

Install only if you are comfortable granting this skill broad local project authority. Prefer using it in a constrained session for advice and documentation lookup, and avoid letting it edit files, run Go/Git commands, or delegate to agents unless you explicitly asked for project changes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:15
Finding

Excessive Tool Permissions Violate Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 15
Vulnerability Type: Excessive tool authorization
Risk Level: Medium

Complete Code Snippet:

yaml
allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent WebFetch WebSearch AskUserQuestion mcp__context7__resolve-library-id mcp__context7__query-docs Bash(godig:*) Bash(gopls:*) LSP mcp__gopls__*

Technical Analysis

The Skill's documented purpose is to recommend and compare Go libraries. That workflow primarily requires reading and searching project files and consulting library documentation. The declared permissions additionally authorize file mutation through Edit and Write, subprocess execution through broad Go, Git, linting, and documentation command families, and action delegation through Agent.

These capabilities exceed the minimum privileges needed for the stated task. In particular:

  • Edit and Write permit modification or creation of project files.
  • Bash(go:*) can invoke project-controlled build steps, tests, generators, or other executable Go workflows.
  • Bash(git:*) can alter repository state and configuration, in addition to performing read-only inspection.
  • Agent allows delegation beyond the direct recommendation workflow.
  • Wildcard command families authorize more operations than individually scoped, read-only commands would.

The reviewed instructions do not direct the agent to misuse these permissions. This finding therefore concerns excessive privilege and expanded attack surface, not confirmed malicious execution.

Attack Path

  1. The Skill is activated while the agent is evaluating a dependency in a repository containing untrusted instructions, source content, generated metadata, or tool configuration.
  2. That untrusted content influences the agent to perform an operation unrelated to library recommendation.
  3. The agent uses an unnecessarily authorized capabilit ...[truncated 942 chars]
Remediation
View remediation

Remediation Suggestions

Apply least privilege to the allowed-tools declaration:

  1. Retain only capabilities required to inspect the project and research library facts, such as Read, Glob, Grep, WebSearch, narrowly constrained WebFetch, and read-only documentation or language-server tools.
  2. Remove Edit and Write because the documented recommendation workflow does not require project mutation.
  3. Remove Agent unless delegation is explicitly required and its security boundaries are documented.
  4. Replace wildcard Bash families with individually approved, read-only commands. Avoid Bash(git:*); if repository inspection is necessary, allow only specific commands such as status or log operations through an enforceable command policy.
  5. Remove Bash(go:*) and other executable tool families unless a separate workflow requires them. If retained, explicitly prohibit generators, installation, arbitrary test execution, and project-controlled build hooks.
  6. Separate advisory and project-modification functionality into different Skills so users can grant elevated permissions only when mutation is explicitly requested.
  7. Add documentation stating that repository content and fetched documentation are untrusted data and must not be treated as executable instructions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.