Back to skill

Security audit

GitHub Pages Auto Deploy

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward GitHub Pages deployment guide with some dependency-pinning caveats, not evidence of hidden or malicious behavior.

Before installing or following this skill, review the GitHub Actions workflow because it will publish website changes automatically after pushes. For safer use, pin GitHub Actions to reviewed commit SHAs, add npm tools as exact-version project dependencies with a lockfile, avoid unreviewed third-party actions unless needed, and consider protected branches or deployment approvals for important sites.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:64
Finding

Unpinned Third-Party Dependencies Allow Supply-Chain Code Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 64-75, 126, 136-139, 150-152, 160, and 188-190
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

The deployment guidance recommends GitHub Actions referenced by mutable major-version tags and npm packages installed or executed without exact versions or integrity controls.

Vulnerable Code

yaml
- name: Checkout
  uses: actions/checkout@v4

- name: Setup Pages
  uses: actions/configure-pages@v4

- name: Upload artifact
  uses: actions/upload-pages-artifact@v3
  with:
    path: 'website'

- name: Deploy to GitHub Pages
  uses: actions/deploy-pages@v4
bash
npm install -g html-minifier clean-css-cli uglify-js
html-minifier --collapse-whitespace website/index.html -o website/index.html
cleancss -o website/style.css website/style.css
uglifyjs website/script.js -o website/script.js
yaml
- name: Cache dependencies
  uses: actions/cache@v3
  with:
    path: ~/.npm
    key: ${{ runner.os }}-npm-${{ hashFiles('**/package-lock.json') }}
yaml
- name: Deploy Preview
  uses: rossjrw/pr-preview-action@v1
  with:
    source-dir: website
bash
npx squoosh-cli website/images/*.jpg --webp auto
yaml
- name: Run Lighthouse
  uses: treosh/lighthouse-ci-action@v9
  with:
    urls: https://yourdomain.com

Technical Analysis

GitHub Action references such as @v4, @v3, @v1, and @v9 are mutable tags rather than immutable commit identifiers. If an upstream repository or publisher account is compromised, an attacker may move or replace a referenced tag so that future workflow runs execute different code from the code originally reviewed.

The command npm install -g html-minifier clean-css-cli uglify-js resolves package versions from the npm registry at execution time. It does not use exact versions, a committed lockfile, or integrity verification. ...[truncated 2331 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every GitHub Action to a reviewed full commit SHA instead of a mutable version tag. Retain the release version in a comment for maintainability, for example:

    yaml
    uses: actions/checkout@REVIEWED_FULL_COMMIT_SHA # v4.x.x
    
  2. Apply SHA pinning to both GitHub-maintained and third-party actions, especially:

    • actions/checkout
    • actions/configure-pages
    • actions/upload-pages-artifact
    • actions/deploy-pages
    • actions/cache
    • rossjrw/pr-preview-action
    • treosh/lighthouse-ci-action
  3. Review third-party action source code and repository ownership before adoption. Prefer first-party actions where equivalent functionality exists.

  4. Add required npm tools as exact-version development dependencies rather than installing them globally:

    bash
    npm install --save-dev --save-exact html-minifier clean-css-cli uglify-js
    
  5. Commit the generated package-lock.json and install dependencies in CI using:

    bash
    npm ci
    
  6. Replace ad hoc npx squoosh-cli execution with a reviewed, exact-version dependency invoked from the locked project installation. Verify the package name, publisher, source repository, and expected integrity before use.

  7. Use dependency update automation that proposes reviewed SHA and version changes rather than silently tracking mutable upstream tags.

  8. Preserve least privilege by granting pages: write and id-token: write only to the deployment job and environment that require them. Configure protected GitHub environments and deployment approvals where appropriate.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 2)May include surrounding context.

md
---
name: github-pages-auto-deploy
description: Auto-deploy websites to GitHub Pages with custom domain support
---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: github-pages-auto-deploy
description: Auto-deploy websites to GitHub Pages with custom domain support
---

# GitHub Pages 自动部署技能

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown instructions and headings are presented entirely in Chinese, and the file does not indicate that the skill is intended only for Chinese-speaking users or provide an opt-in language choice. This can violate a language/locale policy when users are not given a choice of language.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill recommends executing npx squoosh-cli without pinning an exact package version. This can cause non-reproducible builds and exposes users to supply-chain risk if a newer or compromised package version is published and automatically fetched at runtime.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.