Back to skill

Security audit

Github Bounty Hunter

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it is a public GitHub automation tool that lacks enough approval boundaries for actions taken with the user's account.

Review this carefully before installing. It is intended to act through your GitHub account and contains code to post public application comments on issues, but it lacks a preview or confirmation step. Use only a constrained GitHub account or token, review the hardcoded wallet_address in config.json, avoid unattended execution, and expect the current implementation may not actually auto-apply because of a logic bug.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly advertises autonomous proposal submission and wallet management but does not warn users that the skill may take actions affecting external accounts, reputation, or funds. In an agent-skill context, this omission is dangerous because users may run it expecting passive discovery while the tool could perform transactions or submissions on their behalf using stored credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly advertises autonomous proposal submission and automatic PR creation against external platforms, but provides no safety boundaries, approval checkpoints, or disclosure of write actions. That creates a real risk of unauthorized or unintended actions on GitHub and bounty platforms, including spam submissions, low-quality commits, account abuse, and reputational or policy harm to the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill promotes wallet management and use of a GitHub token while omitting basic guidance on secure credential and payment-data handling. In a skill that automates external actions and payment workflows, poor token or wallet handling can expose source-control access, financial destinations, and other sensitive data to theft, misuse, or irreversible payment fraud.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · bounty_hunter.py (reported line 66)May include surrounding context.

python
]
        
        try:
            result = subprocess.run(cmd, capture_output=True, text=True, check=True)
            issues = json.loads(result.stdout)
            
            for issue in issues:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill automatically comments on GitHub issues without any explicit warning, consent prompt, or transaction review. In this context, the capability is more dangerous because it performs public, authenticated actions on behalf of the user, which can spam repositories, damage reputation, or violate platform/project rules.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
84% confidence
Finding

This subprocess call triggers an external side effect: it posts comments to GitHub automatically using the local gh authentication context, without a confirmation gate. In an agent skill context, executing authenticated actions against third-party services can cause unauthorized or unintended account activity even without classic command injection.

Content

Scanner excerpt · bounty_hunter.py (reported line 172)May include surrounding context.

python
"--body", f"/apply\n\n{proposal}"
            ]
            
            subprocess.run(cmd, check=True, capture_output=True)
            
            # Update state
            self.state["applied_bounties"].append({

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module advertises itself as an 'Autonomous bounty discovery and application' tool and should_apply is documented as determining whether to apply, but in the main loop each bounty is added to seen_bounties before should_apply is called. Because should_apply immediately returns False for any seen bounty, the code as written suppresses all applications rather than applying to matching bounties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill persistently stores activity state to a local file without clearly disclosing that behavior to the user. While the stored data is not highly sensitive on its face, undisclosed persistence can leak usage patterns, targets, and timestamps to other local users or processes and violates least-surprise expectations for agent skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.